Showing 2 vulnerabilities on this page for Java-springboot-codebase

Signals CISA KEV Ransomware Nuclei
OsamaTaher vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unauthenticated Arbitrary File Read via Absolute Path

OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive internal files. Commit c835c6f7799eacada4c0fc77e0816f250af01ad2 contains a patch for the issue.

CWE-36May 21, 20251 related artifact
CVSS7.7v4.0EPSS4.05%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE).

CWE-434Nov 14, 2024
CVSS8.7v4.0EPSS3.22%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX