CVE Database
/

CVE-2020-1729

Back to search

CVE-2020-1729

Published: May 28, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2

VendorProductVersions

n/a

SmallRye

affected
SmallRye 1.6.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now