Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

dateCVEdescriptionversionsRisk for Deltares Open ArchiveJIRAupgrade strategy
October 2021

CVE-2020-13936

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet containerup to 202301False positive. Users in thredds are not allowed to upload velocity templates.FEWS-29325
november 2018CVE-2018-1258Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.up to 202301False positive. Spring security is not used.

FEWS-29331,FEWS-29332, FEWS-29334 and FEWS-29335


February 2020CVE-2016-1000027Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.up to 202301False positive. Java is not used for deserialization.

FEWS-29336


November 2022

CVE-2022-3171

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.up to 202301False positive. Parsing is internally handled by THREDDS.

FEWS-29337


December 2022

CVE-2022-45688

A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.up to 202301False positive. XML to json is not used in THREDDS.

FEWS-29340 and FEWS-29342


June 2021

CVE-2021-33813

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.up to 202301False positve. THREDDS is not vulnerable for this type of attack.

FEWS-29346


Apache Tomcat  CVE score Critical and High

...