Alpine Project
Alpine Project Alpine: vulnerabilidades y CVE
Alpine Project Alpine tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-23554 | Media (5.4) | 0.66% | — | 28 dic 2022 | Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint.… |
| CVE-2022-23553 | Alta (7.5) | 0.84% | — | 28 dic 2022 | Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds. |
| CVE-2021-46853 | Media (5.9) | 0.91% | — | 3 nov 2022 | Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS. |
| CVE-2021-38370 | Media (5.9) | 1.6% | — | 10 ago 2021 | In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. |
| CVE-2020-14929 | Alta (7.5) | 1.8% | — | 19 jun 2020 | Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and… |