...
| date | CVE | library | description | versions | Risk for Delft-FEWS | JIRA | upgrade strategy | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
May 2026 | CVE-2026-42198 | postgresql-42.7.10.jar | pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11. | 42.7.10 and lower | Can cause a denial of service on local machine |
| |||||||||||||||||||||||||
April 2026 | CVE-2026-34500 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue. | 11.0.20 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in 2026.01Stable 2024.02 and newer Stable branches since 4th May 2026 | ||||||||||||||||||||||||
April 2026 | CVE-2026-34487 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. | 11.0.20 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in 2026.01Stable 2024.02 and newer Stable branches since 4th May 2026 | ||||||||||||||||||||||||
April 2026 | CVE-2026-34483 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue. | 11.0.20 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in Stable 2024.02 and newer Stable branches since 4th May 2026Library upgraded in 2026.01 | ||||||||||||||||||||||||
April 2026 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue. | 11.0.15 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in 2026.01Stable 2024.02 and newer Stable branches since 4th May 2026 | |||||||||||||||||||||||||
April 2026 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue. | 11.0.19 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in 2026.01Stable 2024.02 and newer Stable branches since 4th May 2026 | |||||||||||||||||||||||||
April 2026 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue. | 11.0.20 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in 2026.01Stable 2024.02 and newer Stable branches since 4th May 2026 | |||||||||||||||||||||||||
April 2026 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue. | 11.0.18 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in 2026.01Stable 2024.02 and newer Stable branches since 4th May 2026 | |||||||||||||||||||||||||
April 2026 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100. Other, unsupported versions may also be affected Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue. | 11.0.18 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in 2026.01Stable 2024.02 and newer Stable branches since 4th May 2026 | |||||||||||||||||||||||||
April 2026 | tomcat-embed-core-11.0.14.jar tomcat-embed-jasper-11.0.14.jar | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue. | 11.0.20 and lower | May effect the patchable webservice otherwise vulnerability is not exposed |
| Library upgraded in 2026.01Stable 2024.02 and newer Stable branches since 4th May 2026 | |||||||||||||||||||||||||
April 2026 | rhino-1.7.14.jar | Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1. | 1.7.14.1 and lower |
| Library upgraded in 2026.01 | ||||||||||||||||||||||||||
April 2026 | sqlite-jdbc-3.50.3.0.jar | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | 3.51.1 and lower |
| Library upgraded in 2026.01 | ||||||||||||||||||||||||||
April 2026 | log4j-*.2.25.3.jar | Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output. | 2.25.3 and lower |
| Library upgraded in 2026.01 | ||||||||||||||||||||||||||
April 2026 | netty-all-4.2.9.Final.jar | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue. | 4.2; versions prior to 4.2.10 | False positive |
| False positive, but updated to 4.2.12Final MAIN(2026.01) | |||||||||||||||||||||||||
April 2026 | netty-all-4.2.9.Final.jar | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue. | 4.2; versions prior to 4.2.10 | False positive |
| False positive, but updated to 4.2.12Final MAIN(2026.01) | |||||||||||||||||||||||||
March 2026 | tomcat-embed-core-11.0.14.jar | Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue. | 11.0.1; versions up to (excluding) 11.0.18 | False positive |
| False positive, but updated to 11.0.18 in MAIN(2026.01) | |||||||||||||||||||||||||
March 2026 | tomcat-embed-core-11.0.14.jar | Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web application. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fix the issue. Tomcat embedded which is part of the FEWS installation is normally not setup for https and should be used only for testing purposes within the protection of a local network so that it should never be exposed to the public internet. | 11.0.1; versions up to (excluding) 11.0.15 | False positive |
| False positive, but updated to 11.0.18 in MAIN(2026.01) | |||||||||||||||||||||||||
January 2026 | CVE-2026-22184 | zlib.dll | This is a bug in a reference program demonstrating how to use zlib. This is not a problem in zlib itself.
| All | False positive |
| False positive, no action required | ||||||||||||||||||||||||
January 2026 | CVE-2025-6444 | client-1.1.5.jar | CVE warnings refer to a JS library, not the service stack in the client jar. | All | False positive |
| False positive, no action required | ||||||||||||||||||||||||
December 2025 | CVE-2024-25710 | commons-compress-1.21.jar | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue. | 1.21 | |||||||||||||||||||||||||||
| December 2025 | CVE-2024-36404 | gt-28.2.jar | GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions 31.2, 30.4, and 29.6 contain a fix for this issue. As a workaround, GeoTools can operate with reduced functionality by removing the `gt-complex` jar from one's application. As an example of the impact, application schema `datastore` would not function without the ability to use XPath expressions to query complex content. Alternatively, one may utilize a drop-in replacement GeoTools jar from SourceForge for versions 31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, and 24.0. These jars are for download only and are not available from maven central, intended to quickly provide a fix to affected applications. | 28.2 | |||||||||||||||||||||||||||
| December 2025 | CVE-2025-30220 | gt-28.2.jar | GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13. | 28.2 | |||||||||||||||||||||||||||
| December 2025 | CVE-2024-1597 | postgresql-42.6.0.jar | pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected. | 42.6.0 | |||||||||||||||||||||||||||
| November 2025 | CVE-2025-59250 | mssql-jdbc.*.jar | Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. | 12.10.2, 13.2.1, 12.6.5, 11.2.4, 10.2.4, 12.8.2, 12.2.1, and 12.4.3 | False positive if non MS-SQL database is used. Otherwise allows man in the middle attack and spoofing when connecting to a MS-SQL server. |
| Upgrade version if MS-SQL is used in branch | ||||||||||||||||||||||||
| Aug 2025 | CVE-2025-6445 | client-1.*.*.jar | ServiceStack FindType Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ServiceStack. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. | All | False positive |
| False positive, no action required | ||||||||||||||||||||||||
| July 2025 | CVE-2024-7254 | protobuf-java-*.jar | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker. | All | False positive |
| False positive, no action required | ||||||||||||||||||||||||
| June 2025 | CVE-2025-52999 | jackson-core-2.13.2.jar | Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources. | 2024.01 and earlier | False positive |
| False positive, no action required | ||||||||||||||||||||||||
| Apr 2025 | CVE-2023-4770 | Delft_PI.jar Delft_Util.jar Delft_NetCDF_Util.jar Delft_Jep.jar mydoggy-res-1.4.3p | An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution. | Adapters | False positive | False positive, no action required | |||||||||||||||||||||||||
| Mar 2025 | CVE-2025-27553 | commons-vfs2-*.jar | Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue. | 2022.01 - current | False positive |
| Upgraded to | ||||||||||||||||||||||||
| Nov 2024 | CVE-2024-48910 | swagger-ui-*.js | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2. | 2021.02 - 2024.01 | False positive |
| False positive, no action required | ||||||||||||||||||||||||
| Oct 2024 | CVE-2024-47554 | commons-io-2.7.jar | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue. | False positive |
| False positive | |||||||||||||||||||||||||
| Sept 2024 | swagger-ui-*.js | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability. | 2021.02 - 2024.01 | False positive |
| False positive, no action required | |||||||||||||||||||||||||
| July 2024 | CVE-2024-36401 | gt-complex-31.1.jar | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions... A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed. | 2021-02 - current | False positive |
| False positive, no action required | ||||||||||||||||||||||||
| May 2024 | bcprov-jdk15-*.jar | The software communicates with a host that provides a certificate, but the software does not properly ensure that the certificate is actually associated with that host. This library is related to the OpenID authentication support in the FEWS web services and admin interface. FEWS only allows the use of certificates from a local truststore which is managed by the system administrators, so the scenario where a certificate is "imported does not apply. Therefore we consider this a false positive. | 2021.02 - 2024.01 | false positive |
| False positive, no action required | |||||||||||||||||||||||||
| February 2024 | nimbus-jose-jwt-9.2*.jar | In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component. This library is related to the OpenID authentication support in the FEWS web services and admin interface. FEWS does not use the PBKDF2 component for password decryption. Therefore we consider this a false positive. | 2022.02 - 2024.01 | false positive |
| False positive, no action required | |||||||||||||||||||||||||
| February 2024 | zlib1.dll | Several security issues in zlib versions 1.2.12 and earlier are reported. FEWS uses a more recent version (1.2.13 - 1.3.1) but apparently the OWASP dependency checker is not able to detect this, therefore we consider this a false alarm. | 2022.02 - current | False positive |
| False positive, no action required | |||||||||||||||||||||||||
| December 2023 | CVE-2022-46337 | derby-10.16.1.1.jar
| A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to execute malware which was visible to and executable by the account which booted the Derby server. FEWS only uses embedded Derby in local Standalone-installations, embedded Derby does not support LDAP and is not accessible over a network in such configurations. Therefore this warning can safely be discarded as a false positive. | 2021.02 - current | False positive |
| False positive, no action required | ||||||||||||||||||||||||
| November 2023 | azure-core-*.jar | Azure CLI REST Command Information Disclosure Vulnerability The Microsoft Security Response Center (MSRC) was made aware of a vulnerability where Azure Command-Line Interface (CLI) could expose sensitive information, including credentials, through GitHub Actions logs. The researcher, from Palo Alto Networks Prisma Cloud, found that Azure CLI commands could be used to show sensitive data and output to Continuous Integration and Continuous Deployment (CI/CD) logs. Microsoft recommends that customers update to the latest version of Azure CLI (2.54) and follow the guidance provided below to help prevent inadvertently exposing secrets through CI/CD logs. A notification in the Azure Portal was sent to customers who recently used Azure CLI commands informing them of an available update. | 2032.02 - current | This is a very specific use case where the role these Java libraries could play is not clear. FEWS is not using this library in the context of a CLI or Github actions so this OWASP alert is considered a false positive. |
| False positive, no action required | |||||||||||||||||||||||||
| November 2023 | CVE-2023-36415 | azure-identity-*.jar | Azure Identity SDK Remote Code Execution Vulnerability For the current 1.11.0 version we consider this a false alert for a vulnerability that needs to be addressed in the .net based Azure SDK. so it will be suppressed, specifically for CVE-2023-36415 | 2021.02 - current | False positive |
| |||||||||||||||||||||||||
| October 2023 | CVE-2023-45853 | zlib1.dll libz.so.1.2.13 | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. | 2022.02 - current | False positive |
| False positive, no action required. | ||||||||||||||||||||||||
| October 2023 | CVE-2023-4586 | netty-transport-4.1.91.Final.jar netty-all-4.1.79.Final.jar | A vulnerability was found in the Hot Rod client provided by the Netty library. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. Hot Rod is a very specific TCP client server protocol used by the Jboss Infinispan product. There is no indication of any kind that the Hot Rod protocol is used by FEWS or THREDDS in any way so this is considered a false positive warning. | 2020.02 - current | False positive |
| False positive. No action required. | ||||||||||||||||||||||||
| September 2023 | CVE-2023-34040 | spring-boot-3.0.7.jar | In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: - The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record - The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. - The user allows untrusted sources to publish to a Kafka topic By default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record. Two out of three conditions mentioned in the description are not met in the case of FEWS. This library is currently only used for the admin interface, which should never be made available for use by "untrusted sources" over the internet. | 2020.02 - 2023.01 | False positive |
| False positive. No action required. | ||||||||||||||||||||||||
| Februari 2023 | CVE-2023-25158 | gt-26.4.jar | The GeoTools implementation of the OpenGIS Filter Encoding Standard (FES) has been found to contain SQL Injection Vulnerabilities when executing OGC Filters with JDBCDataStore implementations. Delft-FEWS has no such JDBCDataStore implementation and the Filter functionality has been included only to support a client side implementation of the OpenGIS WFS interface. FEWS only uses this to implement OpenGIS WFS viewing capability, no server side WFS or FES implementation that could be prone to SQL injection exists in FEWS. | 2019-02 - | False positive |
| False positive. No action required. | ||||||||||||||||||||||||
| December 2022 | CVE-2016-4432 | qpid-jms-client-0.51.0-p.jar | The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging. Delft-FEWS only uses the client, not the AMQP server. | 2021.01 - current | False Positive. |
| False positive. No action required. Jar file can be removed from bin folder if the Azure IOT Hub import is not used. See also AzureIotHub | ||||||||||||||||||||||||
| Oct 2022 | CVE-2022-41853 | hsqldb-2.*.jar | Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. Delft FEWS does not allow any 'untrusted' input to be used in SQL statements, so this is considered a false positive. | 2021.02 - 2022.02 | False positive |
| 2023.01 and later have been upgraded to version 2.7.2 | ||||||||||||||||||||||||
| Oct 2022 | CVE-2022-41404 | ini4j-0.5.4.jar | An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors. | 2022.02 and earlier | False positive | False positive, the report mentions that version 0.5.4 fixes the problem yet the scanners still flags the current version. Also this is only used in adapters where "unspecified vectors" are extremely unlikely to play any role. | |||||||||||||||||||||||||
Feb 2023 August 2022 | CVE-2022-31197 | postgresql-42.4.1.jar postgresql-42.3.3.jar | PG 42.3.3 was flagged in Aug 2022. PG 42.4.1 was flagged only since Feb 2023. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to SQL injection. | 2022.01 - 2022.02 | False Positive. PgResultSet#refreshRow() is not used |
| False positive. 2022.02 and 2023.01 have been upgraded to 42.5.3. | ||||||||||||||||||||||||
| May 2022 | CVE-2016-1000027 | spring-core-5.3.19.jar | The spring framework allows to use a http invoker that uses object serialization that may be vulnerable for Remote Code Execution. | 2022.01 - 2019.02 | Only used in Admin interface where the described scenario is not used. |
| False positive. The HTTP Invoker method that is vulnerable is not used in any of the Delft-FEWS components. Upgrading won't help either since it won't be removed from the library. It has been marked as deprecated and will be removed in spring 6. | ||||||||||||||||||||||||
| Mar 2022 | CVE-2022-26336 | poi-scratchpad 5.2 | A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1. | 2021.02 only | False positive. FEWS uses some of the Apache POI library (for the interval statistics dialog) but not the scratchpad, which is in a separate jar file. |
| False positive. Upgrade in development to latest release. | ||||||||||||||||||||||||
| Feb 2022 | CVE-2022-21724 | postgresql-42.2.22.jar | A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. | 2021.02 - 2022.01 | PG jdbc database url manipulation enables code execution loaded via arbitrary classes. |
| Upgrade to postgresql-42.3.3.jar | ||||||||||||||||||||||||
| Nov 2021 | CVE-2021-43466 | thymeleaf-3.0.12.RELEASE.jar | In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution. Comment of Thymeleaf developer: I'd like to explain that CVE-2021-43466 only affects those applications that contain controllers or controller configurations that take a request parameter and directly use it, without previous filtering, as the name of the view to be rendered | Only used in Admin interface where the described scenario is not used. |
| False positive. No action required. Once version 3.0.13 is available we can upgrade the jar to avoid this false alarm. | |||||||||||||||||||||||||
| Oct 2021 Jan 2022 | tomcat-embed-core-9.0.50.jar | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError. The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore. | 2021.02 - | False positives. Delft-FEWS web applications don't use web sockets and doesn't use session persistence with the FileStorage. |
| False positives Upgrade in development only to latest tomcat 9 release. | |||||||||||||||||||||||||
| Oct 2021 |
| netty-all-4.1.48.Final.jar | The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack. and The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk. | False alarm. Bzip decoder is not used. Excessive memory usage might lead to a failing FSS in the worst case. Since the Azure IOT Hub is quite well secured, the risk is limited. |
| False positive. Upgrade in development to latest release. | |||||||||||||||||||||||||
| Jun 2021 | CVE-2021-33813 | jdom-2.02.jar | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | Might be used in imports that use opendap. But since the library is not used in a service component, the risk is limited. |
| Dependency of ucar netcdf libraries. JDOM library has been upgraded to: jdom2-2.0.6.1.jar since 2022.01. | |||||||||||||||||||||||||
| Oct 2020 | CVE-2017-9096 | iText-2.1.3.jar | The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF. | This library is used only to export timeseries charts and to index PDF help files that are distributed with Delft-FEWS. Untrusted content will never be opened using iText so this is considered a false positive. |
| False positive, upgrading this would require a commercial version that may not be backwards compatible,. | |||||||||||||||||||||||||
| Mar 2019 | CVE-2019-7611 | elasticsearch-core-6.4.3.jar | A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used | Elastic search as distributed as part of the archive server and doesn't have Field Level or Document Level Seurity disabled. As long as the provided settings are not changed, there is no risk. |
| False positive. No need to upgrade since the archive server configuration is correct. Once a fix is available we can upgrade the jar to avoid this false alarm. | |||||||||||||||||||||||||
| May 2018 | CVE-2018-1258 | spring-security-core-5.4.8.jar, spring-security-oauth2-core-5.4.8.jar | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. | False alarm. Spring security is used in the Admin Interface, but doesn't use version 5.0.5 of the spring framework, but a higher version. |
| False positive. No action required. Once a fix is available we can upgrade the jar to avoid this false alarm. |
...