Alpine Project
Alpine Project Alpine: vulnerabilities and CVEs
Alpine Project Alpine has 5 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23554 | Medium (5.4) | 0.66% | — | Dec 28, 2022 | Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint.… |
| CVE-2022-23553 | High (7.5) | 0.84% | — | Dec 28, 2022 | Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds. |
| CVE-2021-46853 | Medium (5.9) | 0.91% | — | Nov 3, 2022 | Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS. |
| CVE-2021-38370 | Medium (5.9) | 1.6% | — | Aug 10, 2021 | In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. |
| CVE-2020-14929 | High (7.5) | 1.8% | — | Jun 19, 2020 | Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and… |