Olingo
Apache · 4 CVEs
CVE-2020-1925
HIGH
olingo-odata: Server side request forgery in AsyncResponseWrapperImpl
Jan 9, 2020
CVE-2019-17555
HIGH
The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it…
Dec 4, 2019
CVE-2019-17556
CRITICAL
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream an…
Dec 4, 2019
CVE-2019-17554
MEDIUM
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolut…
Dec 4, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-1925 | olingo-odata: Server side request forgery in AsyncResponseWrapperImpl | HIGH | 2.83% | Jan 9, 2020 |
| CVE-2019-17555 | The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any… | HIGH | 2.07% | Dec 4, 2019 |
| CVE-2019-17556 | Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserializ… | CRITICAL | 3.62% | Dec 4, 2019 |
| CVE-2019-17554 | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with c… | MEDIUM | 12.25% | Dec 4, 2019 |
Showing 1 to 4 of 4 CVEs