org.apache.any23:apache-any23
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.any23:apache-any23page 1 of 1
- CVE-2021-38555CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.52021-09-11
vulnerable: 0.7.0-incubating ... 2.4 (10 versions)
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allo…
- CVE-2021-40146CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.52021-09-11
vulnerable: 0.7.0-incubating ... 2.4 (10 versions)
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machin…
- CVE-2022-25312CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.72022-03-05
vulnerable: 0.7.0-incubating ... 2.6 (12 versions)
An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability t…
- CVE-2023-34150MEDIUMCVSS 6.5EG 6.52023-07-05
vulnerable: 0.7.0-incubating ... 2.7 (13 versions)
** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.
Check whether org.apache.any23:apache-any23 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.any23:apache-any23 CVEs against the assets you own.
Start Free Scan →