Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-rvm8-j2cp-j592: pf4j vulnerable to remote code execution via loadpluginPath parameter

An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the loadpluginPath parameter.

ghsa
#git#rce

pf4j vulnerable to remote code execution via loadpluginPath parameter

High severity GitHub Reviewed Published Aug 29, 2023 to the GitHub Advisory Database • Updated Aug 29, 2023

ghsa: Latest News

GHSA-x7m9-mv49-fv73: Vaultwarden vulnerable to user impersonation