org.hswebframework.web:hsweb-commons
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.hswebframework.web:hsweb-commonspage 1 of 1
- CVE-2018-20594MEDIUMCVSS 6.1EG 6.12018-12-30
vulnerable: 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4
An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java.
- CVE-2018-20595HIGHCVSS 8.8EG 8.82018-12-30
vulnerable: 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4
A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is s…
Check whether org.hswebframework.web:hsweb-commons is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.hswebframework.web:hsweb-commons CVEs against the assets you own.
Start Free Scan →