| ベンダー | プロダクト | Version Range | ステータス |
|---|---|---|---|
| Apache Software Foundation | Apache JSPWiki | < 2.12.4 | affected |
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Apache Software Foundation | Apache JSPWiki | 0 ~ 2.12.4 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2026-66756 | 6.9 MEDIUM | Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=fal |
| CVE-2026-66755 | 5.9 MEDIUM | Apache Tika: Arbitrary Local File Read in ISArchiveParser |
| CVE-2026-23985 | 5.3 MEDIUM | Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser |
| CVE-2026-23981 | 5.3 MEDIUM | Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification |
| CVE-2026-52680 | Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write | |
| CVE-2026-48910 | Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing | |
| CVE-2026-28814 | Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering | |
| CVE-2026-28813 | Apache JSPWiki: JSPWiki vulnerable to JSON hijacking | |
| CVE-2026-28811 | Apache JSPWiki: Error Handling - Reveals Error Details | |
| CVE-2026-44617 | Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867 | |
| CVE-2026-44616 | Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction | |
| CVE-2026-44613 | Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling |
まだコメントはありません