Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Orangetwo

#17789of 53,638
15.1Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2018-18896
5.3
2018-03-31
Apache · Apache Spark · CVE-2018-9159
**Name of the Vulnerable Software and Affected Versions** Apache Spark versions prior to 2.7.2 **Description** A remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. **Recommendations** For versions prior to 2.7.2, update to version 2.7.2 or later to resolve the issue.
PT-2018-18428
9.8
2018-03-14
Pyeve · Eve · CVE-2018-8097
Name of the Vulnerable Software and Affected Versions: Eve (aka pyeve) versions prior to 0.7.5 Description: The issue allows remote attackers to execute arbitrary code via Code Injection in the `where` parameter. This is related to the `io/mongo/parser.py` file in Eve. Recommendations: For versions prior to 0.7.5, update to version 0.7.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the `where` parameter in the affected API endpoint until the issue is resolved.