Threats Tagged 'cwe-917'
View all threats tagged with 'cwe-917'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-917'
Click on any threat for detailed analysis and mitigation recommendations
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script. Join the discussion | CVE Database V5 | 06/24/2026, 13:20:04 UTC Added: 06/24/2026, 13:54:28 UTC |
CVE-2026-11561 is a critical vulnerability in Soagen Informatics Technologies Software and Consulting Inc.'s Apinizer product. It involves improper neutralization of special elements used in an expression language statement, leading to expression language injection and potential code injection. The affected versions include Apinizer 2026.04.0 through versions before 2026.04.6. The vulnerability has a CVSS score of 9.8, indicating high severity with network attack vector, low attack complexity, no privileges required, no user interaction, and full confidentiality, integrity, and availability impact. No official patch or remediation guidance is currently available from the vendor. No known exploits in the wild have been reported. Join the discussion | CVE Database V5 | 06/11/2026, 12:28:27 UTC Added: 06/11/2026, 12:52:42 UTC |
0 Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1. Join the discussion | CVE Database V5 | 06/11/2026, 05:02:53 UTC Added: 06/11/2026, 05:16:38 UTC |
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key is embedded directly into a SpEL expression without sanitization or validation. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5. Join the discussion | CVE Database V5 | 06/10/2026, 00:31:52 UTC Added: 06/09/2026, 23:55:53 UTC |
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19. Join the discussion | CVE Database V5 | 06/09/2026, 23:48:42 UTC Added: 06/09/2026, 23:55:50 UTC |
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder. Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19. Join the discussion | CVE Database V5 | 06/09/2026, 23:48:38 UTC Added: 06/09/2026, 23:55:50 UTC |
0 An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown. Join the discussion | CVE Database V5 | 05/19/2026, 14:12:06 UTC Added: 05/19/2026, 14:36:42 UTC |
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown. Join the discussion | CVE Database V5 | 05/19/2026, 14:03:18 UTC Added: 05/19/2026, 14:36:42 UTC |
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Join the discussion | CVE Database V5 | 05/19/2026, 09:24:39 UTC Added: 05/19/2026, 10:06:42 UTC |
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 through latest 1.1.x; upgrade to 1.1.6 or greater. Join the discussion | CVE Database V5 | 05/09/2026, 00:34:17 UTC Added: 05/09/2026, 01:22:36 UTC |
Showing 1 to 10 of 17 results