Apache Software Foundation Apache Cocoon vulnerabilities
3 known vulnerabilities affecting apache_software_foundation/apache_cocoon.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1
Vulnerabilities
Page 1 of 1
CVE-2025-24783HIGHCVSS 7.5≤ *2025-01-27
CVE-2025-24783 [HIGH] CWE-335 CVE-2025-24783: ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vu
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon.
This issue affects Apache Cocoon: all versions.
When a continuation is created, it gets a random identifier. Because the random number generator used to generate these identifiers was seeded with the startup time, it may
cvelistv5nvd
CVE-2023-49733CRITICALCVSS 9.8≥ 2.2.0, < 2.3.02023-11-30
CVE-2023-49733 [CRITICAL] CWE-611 CVE-2023-49733: Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affe
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.
Users are recommended to upgrade to version 2.3.0, which fixes the issue.
cvelistv5nvd
CVE-2022-45135CRITICALCVSS 9.8≥ 2.2.0, < 2.3.02023-11-30
CVE-2022-45135 [CRITICAL] CWE-89 CVE-2022-45135: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.
Users are recommended to upgrade to version 2.3.0, which fixes the issue.
cvelistv5nvd