Repository navigation
PD-14292 Omit contributor email from API work reads - #7755
Conversation
|
Semgrep found 3
🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.httpcomponents.core5:httpcore5-h2 are vulnerable to Uncontrolled Resource Consumption. The HTTP/2 stream multiplexer initializes its HPACK decoder with the protocol initial SETTINGS_MAX_HEADER_LIST_SIZE of Integer.MAX_VALUE instead of the locally configured limit, so the configured maximum header list size is not enforced until the peer acknowledges the local SETTINGS frame. A remote peer can send an oversized compressed header block during that pre-acknowledgement window to force unbounded memory allocation and cause a denial of service. Both HTTP/2 clients and servers are affected, and the default configuration is vulnerable because the limit it specifies is ignored during that same window. Fix: Upgrade this library to at least version 5.4.3 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:129. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41095, GHSA-v3jc-474w-2wm6, CVE-2026-54428 Semgrep found 3
🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. Apache ActiveMQ fails to fully validate non-parenthesized composite discovery wrappers (e.g. Fix: Upgrade this library to at least version 6.2.6 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:150. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33576, GHSA-v853-w46p-fv2h, CVE-2026-34197, CVE-2026-45505 Semgrep found 3
🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default access policy that permits exec operations on ActiveMQ MBeans. An authenticated attacker can invoke BrokerService.addNetworkConnector(String) with a crafted discovery URI that abuses the VM transport brokerConfig parameter (via a masterslave:// URL) to load an attacker-controlled Spring XML application context, achieving arbitrary code execution through bean factory methods such as Runtime.exec(). Upgrade to 5.19.7 or 6.2.6. Fix: Upgrade this library to at least version 6.2.6 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:150. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33577, GHSA-hg6c-8mvr-jqc9, CVE-2026-42588 Semgrep found 3
🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Control of Generation of Code ('Code Injection') / Improper Input Validation. An authenticated attacker can bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via Fix: Upgrade this library to at least version 6.2.5 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:150. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25410, GHSA-w3w2-mpp5-92gm, CVE-2026-40466 Semgrep found 3
🟠 High severity issue identified in your code: Risk: Affected versions of org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, and org.apache.activemq:apache-activemq are vulnerable to Improper Input Validation. An authenticated attacker can exploit this vulnerability by using the Apache ActiveMQ admin web console to construct a malicious broker name that bypasses name validation to include an xbean binding. The attacker can then use the DestinationView mbean to send a message that triggers a VM transport creation referencing the malicious broker name, causing Spring ResourceXmlApplicationContext to load a remote Spring XML application context. Because Spring instantiates all singleton beans before BrokerService validates the configuration, this leads to arbitrary code execution on the broker JVM through bean factory methods such as Runtime.exec(). Fix: Upgrade this library to at least version 6.2.5 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:150. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25412, GHSA-mr6m-xj7v-3cv3, CVE-2026-41044 Semgrep found 2 🟠 High severity issue identified in your code: Risk: Affected versions of org.eclipse.jetty.http2:http2-common and org.eclipse.jetty.http2:jetty-http2-common are vulnerable to Allocation of Resources Without Limits or Throttling / Uncontrolled Resource Consumption. A malicious HTTP/2 client can send malformed control frames (for example, WINDOW_UPDATE frames with a zero or overflow increment, HEADERS/DATA on half-closed streams, or mis-framed PRIORITY frames) to Eclipse Jetty's HTTP/2 server, triggering RST_STREAM responses that prematurely decrement the active‐stream counter. This lets an attacker repeatedly open new streams on a single connection without ever hitting the max-concurrent-streams limit, exhausting CPU and/or memory and resulting in denial of service. This is a protocol level attack. Fix: Upgrade this library to at least version 9.4.58 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:37. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25397, GHSA-mmxm-8w33-wc4h, CVE-2025-5115 Semgrep found 2 🟠 High severity issue identified in your code: Risk: protobuf-java and protobuf-javalite 3.21.x before 3.21.7, 3.20.x before 3.20.3, 3.19.x before 3.19.6, 3.16.x before 3.16.3 are vulnerable to a Denial of Service (DoS) attack through specially crafted input messages. It is recommended to upgrade protobuf-java and protobuf-javalite 3.21.x to 3.21.7, 3.20.x to 3.20.3, 3.19.x to 3.19.6, and 3.16.x to 3.16.3. Fix: Upgrade this library to at least version 3.19.6 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:224. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7625, GHSA-g5ww-5jh7-63cx, CVE-2022-3509 Semgrep found 2 🟠 High severity issue identified in your code: Risk: Affected versions of org.eclipse.jetty.http3:http3-qpack, org.eclipse.jetty:jetty-http, and org.eclipse.jetty.http2:http2-hpack are vulnerable to Integer Overflow Or Wraparound. An attacker can exploit the integer overflow in Fix: Upgrade this library to at least version 9.4.53 at ORCID-Source/orcid-api-web/maven_dep_tree.txt:38. Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2828, GHSA-wgh7-54f2-x98r, CVE-2023-36478 |
No description provided.