GHSA-54fx-gm74-q676
Dashboard / Vulnerabilities / GHSA-54fx-gm74-q676
Summary: Permissions bypass in SmallRye
Details: A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2
References: https://nvd.nist.gov/vuln/detail/CVE-2020-1729, https://github.com/smallrye/smallrye-config/commit/fb0def6f61c09a2a80c9145e4ec6521225cd0b99, https://bugzilla.redhat.com/show_bug.cgi?id=1802444
Affected packages
Package
Name: io.smallrye.config:smallrye-config
Purl: pkg:maven/io.smallrye.config/smallrye-config
Affected ranges
Type: ECOSYSTEM
Events:
