Jython Project Jython vulnerabilities
3 known vulnerabilities affecting jython_project/jython.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-16935MEDIUMCVSS 6.1≥ 0, < 2.7.2+repack1-52019-09-28
CVE-2019-16935 [MEDIUM] CVE-2019-16935: The documentation XML-RPC server in Python through 2
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.
osv
CVE-2016-4000CRITICALCVSS 9.8v2.7.02017-07-06
CVE-2016-4000 [CRITICAL] CWE-502 CVE-2016-4000: Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunctio
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
nvdosv
CVE-2013-2027MEDIUMCVSS 4.6v2.2.12015-02-13
CVE-2013-2027 [MEDIUM] CWE-264 CVE-2013-2027: Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows loc
Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
nvdosv