Redhat Jboss Aerogear vulnerabilities
3 known vulnerabilities affecting redhat/jboss_aerogear.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2014-3648HIGHCVSS 7.5v1.0.02022-07-01
CVE-2014-3648 [HIGH] CWE-400 CVE-2014-3648: The simplepush server iterates through the application installations and pushes a notification to th
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those endpoints can't be reached or can slow the server down by purposefully wasting it's
nvd
CVE-2014-3650MEDIUMCVSS 5.4v1.0.02022-07-01
CVE-2014-3650 [MEDIUM] CWE-79 CVE-2014-3650: Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.
nvd
CVE-2014-3649MEDIUMCVSS 6.1≤ 2014-09-192019-11-04
CVE-2014-3649 [MEDIUM] CWE-79 CVE-2014-3649: JBoss AeroGear has reflected XSS via the password field
JBoss AeroGear has reflected XSS via the password field
nvd