Skip to main content

Vendor/product archive

apache / brooklyn CVEs

Beta · best-effort

3 CVEs tagged to apache / brooklyn0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2017-3165

Published Sep 13, 2017

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user author…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8744

Published Sep 13, 2017

Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the d…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8737

Published Sep 13, 2017

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to produce a link which, if clicked w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1