Detect and fix risks
The Agentless Detection feature supports security risk assessment of cloud servers without installing the Security Center agent. The feature scans server disk snapshots or images, and combines AI sandbox dynamic analysis to perform multi-dimensional security detection such as vulnerabilities, malware, configuration baselines, and sensitive files in an isolated environment. It also supports AI vulnerability fixing. This process has almost no impact on server performance.
Scope
Supported asset types:
Chinese Mainland region: You can scan Alibaba Cloud Elastic Compute Service (ECS) instances, cloud disk snapshots, or custom images, along with AWS EC2 instances.
Outside Chinese Mainland regions: You can scan Alibaba Cloud ECS instances, cloud disk snapshots, and custom images, along with AWS EC2 instances and Azure virtual machines.
Supported regions for Alibaba Cloud servers:
China (Qingdao), China (Beijing), China (Zhangjiakou)
China (Hangzhou) and China (Shanghai)
China (Shenzhen)
China (Chengdu)
China (Hong Kong), Singapore, US (Virginia), Indonesia (Jakarta)
Operating system compatibility: For a detailed list of operating systems that support vulnerability scanning, see Supported operating systems for vulnerability scanning.
NoteFreeBSD operating systems do not support baseline checks, malicious sample detection, or sensitive file detection.
Supported vulnerability fix types: Only the application vulnerability type can be fixed. For the detailed list of supported vulnerabilities, see Vulnerability fix support list.
NoteThe vulnerability fixing capability is continuously evolving. For the most accurate information, refer to the console.
Connect detection assets
Alibaba Cloud assets
Agentless Detection automatically synchronizes assets under the current Alibaba Cloud account. No manual operation is required.
Multicloud assets
Connect to Amazon Web Services (AWS) or Azure for Agentless Detection:
Connect to AWS
Prepare AWS access credentials
In your AWS account, create an IAM user with programmatic access and obtain the Access Key ID and Secret Access Key. This user needs permissions to access and create EC2 snapshots.
ImportantTo use the Agentless DetectionAgentless Detection feature, create a custom IAM policy in your AWS account with the permissions described in Create a custom policy for Agentless Detection.
Configure the connection method
Go to the Agentless DetectionAgentless Detection page. On the Server Check tab, in the Add Multi-cloud Asset section, click Add below the
icon.On the Add Assets Outside Cloud page, complete the configuration on the Create Sub-account page as described below and click Next.
Solution Selection: Manual Configuration.
Permission Description: Select Agentless DetectionAgentless Detection.
Submit credential information
On the Submit AccessKey Pair tab, accurately enter the credentials that you created in AWS and click Next.
Sub-account SecretID and Sub-account SecretKey: Enter the AWS sub-account API key information that you obtained in Step 1.
Connection Region: Select an available region. The system uses the selected region to verify asset accessibility and retrieve corresponding cloud resource data.
Domain: Configure this parameter based on the selected connection region. For AWS China regions, select China. For all other regions, select International.
Configure policy
On the Policy Configuration tab, complete the configuration as described below.
Select region: Select the AWS region where the assets you want to onboard are located.
NoteAsset data is automatically attributed to the data center corresponding to the region selected in the upper-left corner of the Security Center console.
Chinese Mainland: Chinese mainland data center.
Outside Chinese Mainland: Singapore data center.
Region Management: Recommended. After selected, assets in new regions under this AWS account will be automatically synchronized without manual configuration.
AK Service Status Check: Set the interval for Security Center to automatically check the validity of the AWS account API key. You can select "Off" to disable detection.
Click OK.
After completing permission verification and policy configuration, create Agentless Detection tasks for your AWS EC2 instances.
Connect to Azure
Prepare Azure access credentials
In the Azure portal, create an app registration and grant it subscription-level access permissions. Obtain the following credentials: Application (client) ID, Directory (tenant) ID, and the client secret Value.
ImportantTo use the Agentless DetectionAgentless Detection feature, grant the Reader and Disk Snapshot Contributor roles to Security Center in your Azure account. For specific operations, see Add Azure assets.
Configure the connection method
In the upper-left corner of the console, select the Outside Chinese Mainland region.
Go to the Agentless DetectionAgentless Detection page. On the Server Check tab, in the Add Multi-cloud Asset section, click Add below the
icon.Go to the Add Assets Outside Cloud page. In the Create Sub-account step, select Agentless DetectionAgentless Detection in the Permission Description section and click Next.
Submit credential information
In the Submit AccessKey Pair tab, accurately enter the credentials that you created in Azure, and then click Next.
Enter an AppID: The Application (client) ID that you obtain from your Azure application registration.
Enter a password: The client secret value obtained from your Azure app registration.
Tenant ID: The Directory (tenant) ID from your Azure application registration.
Domain (Select Chinese Edition for China and International Edition for others): For 21Vianet users, select the Chinese Edition.
Configure policy
On the Policy Configuration tab, complete the configuration by referring to the following instructions.
Select region: Select the regions where the Azure assets to be onboarded are located.
NoteAsset data is automatically stored in the data center corresponding to the region selected in the upper-left corner of the Security Center console.
Chinese Mainland: Data center in Chinese Mainland.
Outside Chinese Mainland: Data center in Singapore (Singapore).
Region Management: We recommend that you select this option. After you select this option, assets in new regions added to this Azure account in the future will be automatically synchronized without manual configuration.
AK Service Status Check: Set the interval for Security Center to automatically check the validity of the Azure account credentials. You can select Off to disable the check.
After completing permission verification and policy configuration, create Agentless Detection tasks for your Azure virtual machines.
Create and run detection tasks
Configure detection whitelists (optional)
On the Agentless DetectionAgentless Detection page, click Scan Configuration, and then click the Manage Whitelist tab.
Based on the risk type, click Create Rule on the corresponding tab.
Configure the whitelist rule as described below.
ImportantThe following whitelist configurations apply to all assets.
Vulnerability whitelist
Vulnerability Type: Only Linux Software Vulnerability, Windows System Vulnerability, and Application Vulnerability are supported.
Vulnerability Name: The latest vulnerability data is retrieved based on the selected Vulnerability Type.
Malicious sample whitelist
Alert Name: The default value is ALL, which means that the whitelist rule applies to all alert types. This value cannot be changed.
Allowlist Field: The default value is fileMd5, which means that files are whitelisted by MD5 hash. This value cannot be changed.
Wildcard Character: Only Equal is supported.
Rule Content: Enter the MD5 hash of the file.
Baseline whitelist
Check Item Type: Specify the type of baseline check items to exclude from detection.
Check Item: Specific check items are retrieved based on the selected Check Item Type.
Sensitive file whitelist
Check Item for Sensitive Files: Specify the items to exclude from detection.
Configure Whitelist Conditions:
NoteYou can configure multiple rules. The rules have an AND relationship. A file is added to the whitelist only if it meets all rule conditions.
MD5: For the wildcard, only Equal is supported. Then, enter the MD5 hash of the file.
Path: For the wildcard, Contains, Prefix, and Suffix are supported. Then, enter the path.
Create a detection task
Agentless Detection supports two task types: on-demand and scheduled.
Immediate detection task
Use these tasks for one-time security scans of specific assets.
Host security scan
On the tab, in the Risk Detection section, click Scan Now.
In the Scan Now panel, configure the settings as described below, and then click OK.
Scan Scope: We recommend that you select the data disks. More complete data sources improve the detection of vulnerabilities, alerts, and other risks.
Snapshot/Image Storage Time:
Valid values: 1 to 365. Unit: days.
You are charged for creating snapshots or images. The longer you retain the snapshots or images, the higher the fees.
ImportantIf you select Retain Only At-risk Snapshots or Images, the system automatically deletes risk-free snapshots or images after the scan is complete.
After you create the task, Security Center automatically creates snapshots or images and runs the scan. If risks are detected after the scan, the system also automatically triggers parallel sandbox analysis. For more information, see Automatic creation of snapshots and images and Automatically run AI parallel sandbox analysis. For information about how to view task progress and reports, see View task progress and reports.
NoteThe more server data that is scanned, the longer the task takes. Wait for the task to complete.
Snapshot security scan
To use snapshots for detection, first enable the snapshot feature. For more information, see Enable snapshots.
On the tab, in the Risk Detection section, click Scan Now.
In the Scan Now panel, select the target snapshot, and then click OK.
Custom image security scan
On the tab, in the Risk Detection section, click Scan Now.
In the Scan Now panel, select the target image, and then click OK.
NoteIf the image that you want to scan does not appear in the detection task panel, go to the page and click Synchronize Assets. After synchronization is complete, repeat this step.
Scheduled detection tasks
Use scheduled tasks to run regular, automated security inspections of asset groups.
Go to the configuration page
In the upper-right corner of the Agentless DetectionAgentless Detection page, click Scan Configuration.
Configure the detection scope
On the Security Check Scope tab, configure the settings as described below, and then click Save.
Baseline Check Scope: Click Manage to go to the Baseline Check Configuration page, where you can view and configure the supported baseline check scope.
Sensitive File: Click Manage to go to the Sensitive File Scan Settings page, where you can view and configure check items.
ImportantIf you select Default Scan for New Check Items, the system automatically scans new check items when they are added.
Configure the detection policy
On the Automatic Detection Policy tab, configure the settings as described below, and then click Save.
Check Host: Configure the assets to scan as described below. For information about the other settings, see Host security scan.
Configure Scan Cycle:
Set how often the detection task runs, such as daily or weekly.
If you select Do Not Scan, the Check Host task is paused.
After you configure the schedule, the system starts running scan tasks the next day.
Configure Scan Assets:
In the Scan Assets section, click Management.
Default Scan for New Assets: We recommend that you select this option. The system then automatically includes newly added servers in the next scan cycle without requiring you to add them manually.
Adjust the detection scope: In the asset list, select or clear specific servers as needed to configure the asset scope of the detection task.
Snapshot-based Check/Custom Image Check: If you turn on Incremental Check, the system automatically runs incremental scans on snapshots or custom images that have not been scanned.
ImportantIncremental detection requires Data Delivery of ActionTrail. On the tab, turn on Data Delivery of ActionTrail. For more information, see the authorization configuration instructions.
Automatic creation of snapshots and images
When you execute a Server Check task, the system uses the service-linked role AliyunServiceRoleForSas to perform the following automated operations:
Create a snapshot or image: The system automatically creates a temporary server snapshot with a name that starts with
SAS_Agentless.Share securely: The system shares the snapshot or image with the official Security Center service account for scanning and analysis.
Automatic cleanup: After the scan is complete and the Snapshot/Image Storage Time expires, the snapshot or image is automatically deleted and sharing is canceled.
NoteThe snapshot or image is used only for security scanning, and no fees are incurred for sharing.
In Event Query in the ActionTrail console, you can view a record of AliyunServiceRoleForSas creating a snapshot or image.
View snapshots: On the Cloud Disk Snapshots page in the ECS console, you can view the temporary snapshots automatically created by Security Center. The snapshot name starts with
SAS_Agentless, its Status is Available, its Retention Period is 7 days, and its upload progress to OSS is 100%.
Automatically run AI parallel sandbox analysis
After a detection task is complete, the system automatically creates a parallel sandbox analysis task. You can view the task progress and download analysis reports in Task Management. For specific operations, see View task progress and reports.
Trigger conditions: The following conditions must be met at the same time.
The host security detection, snapshot security detection, or custom image security detection task is complete.
Risks such as vulnerabilities, baselines, and sensitive files exist in the detection results.
Trigger method: Parallel sandbox analysis is automatically triggered by the system and cannot be manually executed.
View task progress and reports
In the upper-right corner of the Agentless DetectionAgentless Detection page, click Task Management.
In the pop-up Task Management panel, select the tab based on the detection type.
Server Check/Snapshot-based Check/Custom Image Check
View status and progress: In the list on the corresponding tab, view the task Status and Progress.
View and download reports:
Download the report for an entire task: In the Actions column of the target task, click Download Report.
Download the report for a single server:
In the Actions column of the target task, click Details or View.
In the Task Details panel, click Download Report in the Actions column.
Parallel Sandbox Analysis
View status and progress: In the list on the Parallel Sandbox Analysis tab, view the task Status and Progress.
View and download reports:
In the Actions column of the target task, click Details.
On the Task Details page, click Download Report in the asset Actions column.
Analyze and handle risks
After a task is successfully completed, you can view and handle the detected security risks on the Agentless Detection page.
If the same server is scanned multiple times, only the most recent scan results are displayed. Older results are overwritten.
View risk details
On the Agentless DetectionAgentless Detection page, go to the tab for the detection policy, such as Server Check, and then go to the tab for the risk type, such as Vul Risk. In the list, find the risk item and click View or Details in the Actions column to view its details.
Handle risk alerts
NoteWhitelist rules that you create when analyzing and handling risks are also automatically synchronized to the detection whitelist, where you can modify, delete, or otherwise manage them.
Vulnerability risks
Procedure:
Add to Whitelist: Locate the vulnerability that you want to handle and click Add to Whitelist in the Actions column.
Fix vulnerabilities:
Create a fix task:
On the Application Vulnerability tab, locate the vulnerability that you want to fix and click Fix in the Actions column.
In the Affected Asset section of the vulnerability Details tab, click Fix in the Actions column of the target asset. To fix the vulnerability on multiple assets at a time, select the assets and click Fix below the list.
On the vulnerability fix confirmation page, confirm the Asset Information and Fixed Custom Image Name.
Bulk Fix other vulnerabilities (optional): If the custom images have other fixable vulnerabilities, select the vulnerabilities to fix them together with the current vulnerability in the same task. The fixes are included in the new image that corresponds to each custom image.
After you confirm that the information is correct, click Fix Now.
View and download fix results:
View results and progress:
Return to the Agentless DetectionAgentless Detection homepage and click Task Management in the upper-right corner.
On the Fix Task tab, view the fix Status and Progress.
View and download the report
If the fix succeeds, click Details in the task Actions column.
On the Task Details page, click View Fix Report in the asset Actions column.
On the report page, click the download icon in the upper-right corner.
Handling instructions:
Add to whitelist:
After you add a vulnerability to the whitelist, alerts are no longer generated for the vulnerability. Proceed with caution.
After you add a vulnerability to the whitelist, the system automatically synchronizes it to the tab. You can view the added entry on that tab.
Fix vulnerabilities:
Only some vulnerabilities can be fixed.
Vulnerability fixing is billed separately, and no fee is incurred if you do not use it. The price is CNY 10 per vulnerability. For more information, see the vulnerability fixing billing documentation.
Baseline checks
Procedure: In the check item list, locate the check item that you want to handle and click Add to Whitelist in the Actions column.
Handling instructions: Add to whitelist.
After you add a check item to the whitelist, newly added servers are no longer scanned for that item. Proceed with caution.
After you add a check item to the whitelist, the system automatically synchronizes it to the tab. You can view the added entry on that tab.
Malicious samples
Procedure:
Handle new alerts: Set the handling status in the filter to Unhandled, and then click Handle in the Actions column of the target alert.
Review or revise archived alerts: Set the handling status in the filter to Handled, and then click Change Status in the Actions column of the target alert.
Handling instructions:
Add to Whitelist: If you confirm that an alert does not involve malicious behavior, you can add it to the whitelist based on the whitelist rule and application scope.
ImportantIf you add an alert to the whitelist, future occurrences of the same alert are automatically moved to the handled list and no notifications are sent. Proceed with caution.
You can handle identical alerts in batches. The supported handling methods vary by alert type. Refer to the console for the available methods.
After you add an alert to the whitelist, the system automatically synchronizes it to the tab. You can view the added entry on that tab.
Manually Handled: After you manually resolve the risk that caused the alert, mark the alert as Manually Handled.
Mark as False Positive: Mark the current alert as a false positive. Security Center uses your feedback to continuously improve its scanning capabilities.
Ignore: Ignore only the current alert. If a subsequent scan matches the detection policy, another alert is generated.
Sensitive files
Procedure:
In the sensitive file alert list, locate the alert that you want to handle and click Details in the Actions column to view the detailed description and hardening recommendations.
In the operation column of the risk list on the details panel, click Handle. In the dialog box, select a method to handle the alert and click OK.
Handling instructions:
Add to Whitelist: If you confirm that an alert does not involve malicious behavior, you can add it to the whitelist based on the whitelist rules. The following rules apply:
ImportantIf you add an alert to the whitelist, future occurrences of the same alert are automatically moved to the handled list and no notifications are sent. Proceed with caution.
You can configure multiple rules. All rules are combined by using the AND operator. An alert is added to the whitelist only if all rule conditions are met.
After you add an alert to the whitelist, the system automatically synchronizes it to the tab. You can view the added entry on that tab.
MD5: The wildcard condition supports only Equals. Enter the MD5 hash of the file.
Path: The wildcard condition supports Contains, Starts With, and Ends With. Enter the specific path.
Manually Handled: After you manually resolve the risk that caused the alert, mark the alert as Manually Handled.
Mark as False Positive: Mark the current alert as a false positive. Security Center uses your feedback to continuously improve its scanning capabilities.
Ignore: Ignore only the current alert. If a subsequent scan matches the detection policy, another alert is generated.
Troubleshoot failed tasks
If a task has an abnormal status, you can view the failure reason on the Task Details page and refer to the following table for solutions.
Failure message | Cause of failure | Solution |
The current region is not supported | The specified region is not supported. | Confirm that the region of the ECS instance is supported. For more information, see Scope. |
Failed to connect to the disk | A temporary error occurred when the system was mounting the snapshot disk. | In the Actions column of the task, click Retry. |
Failed to create the image | The number of ECS images has reached the quota limit. | Increase the image quota in the ECS console or delete old images that are no longer in use. |
Task processing timed out | The scan volume was too large or the system was busy, causing a timeout. | Split the task into multiple subtasks based on the scan scope, and then run them again. |
Performance impact and cost control
Performance impact: The Agentless Detection scanning process does not consume resources of the target server.
Cost control: Agentless Detection fees consist of "scanning + AI sandbox analysis" fees and snapshot/image storage fees. If you use AI vulnerability repair, an additional repair fee is charged based on the number of successful repairs. To effectively control costs, we recommend the following configurations:
When you create a task and configure the Snapshot/Image Storage Time setting, select Retain Only At-risk Snapshots or Images.
Regularly clean up snapshots that are no longer needed.
Quotas and limits
Disk specifications: A single cloud disk supports a maximum of 1 TiB. A maximum of 20,000,000 files can be scanned on a single disk. Any files beyond this limit will not be scanned.
Server limits: Each server supports scanning a maximum of 15 cloud disks. Any disks beyond this limit will not be scanned.
Result retention: Detection results are retained for 30 days and automatically cleared upon expiration. For multiple scans of the same asset, only the most recent results are retained.
Compressed file limits: Only JAR files are supported. Only the first layer is decompressed for scanning.
File system limits: ext2, ext3, ext4, XFS, and NTFS are supported. For NTFS, check items that rely on file permission information are not supported.
Storage and disk limits: For all hosts (Alibaba Cloud and non-Alibaba Cloud), scanning data disks that use LVM (Logical Volume Manager), RAID arrays, or the ReFS file system is not supported.
Appendix
Detailed detection capabilities
The following table lists the main detection items supported by Agentless Detection.
Detection Category | Detection Scope | Details |
Vulnerabilities | Linux software vulnerabilities, Windows system vulnerabilities, application vulnerabilities | For supported operating system versions, see Supported operating systems for vulnerability scanning. |
Baseline Check | Configuration compliance for operating systems, applications, and databases | Supports scanning hundreds of configuration items, including but not limited to:
For more information, go to the Scan Configuration page in the console. For details about the operations, see Baseline Check Scope. |
Malicious Sample | Malicious scripts, webshells, malware |
See Malicious samples. |
Sensitive File | Credential information, key files, configuration files | Supports detection of common sensitive files, including but not limited to:
For more information, go to Scan Configuration in the console. For specific steps, see sensitive file check item. |
Supported operating systems for vulnerability scanning
Operating System Type | Version |
Windows Server |
|
Red Hat |
|
CentOS |
|
Ubuntu |
|
Debian |
|
Alpine |
|
Amazon Linux |
|
Oracle Linux |
|
SUSE Linux Enterprise Server |
|
Fedora Linux |
|
openSUSE |
|
Malicious samples
Malicious sample category | Description | Supported detection items |
Malicious scripts | Detects whether system functions on an asset have been attacked or tampered with by malicious scripts and displays possible malicious script attacks in the detection results. Malicious scripts are classified as file-based or fileless scripts. After attackers obtain permissions on a server, they use scripts as vehicles for further attacks. For example, attackers may implant mining programs, add system backdoors, or add system accounts. | Supported languages include Shell, Python, Perl, PowerShell, VBScript, and BAT. |
WebShell | Checks whether web script files on an asset are malicious or provide backdoor communication or management capabilities. After implanting a WebShell, an attacker can control the server and use the WebShell as a backdoor for further attacks. | Supported languages include PHP, JSP, ASP, and ASPX. |
Malware | Checks whether binary files on an asset are malicious and can damage the asset or maintain persistent control. After implanting a malicious binary file, an attacker can control the server to mine cryptocurrency, launch DDoS attacks, or encrypt asset files. Based on function, malicious binaries mainly include mining programs, Trojans, backdoor programs, hacker tools, ransomware, and worms. | Compromised basic software |
Suspicious program | ||
Spyware | ||
Trojan program | ||
File-infecting virus | ||
Worm | ||
Exploit program | ||
Metamorphic Trojan | ||
Hacker tool | ||
DDoS Trojan | ||
Reverse shell backdoor | ||
Malicious program | ||
Rootkit | ||
Downloader Trojan | ||
Scanner | ||
Riskware | ||
Proxy tool | ||
Ransomware | ||
Backdoor program | ||
Mining program |
Vulnerability fix support list
Vulnerability ID | Description |
CVE-2018-1257 | In the spring-messaging module of Spring Framework, when WebSocket endpoints are exposed through an in-memory STOMP broker, attackers can craft messages to cause a regular expression denial of service (ReDoS) attack. |
CVE-2019-12415 | In Apache POI 4.1.0 and earlier versions, the XSSFExportToXml tool can process a malicious Excel document to read local files or intranet resources through XML external entity (XXE) injection when converting user-provided Excel documents. |
CVE-2019-14439 | FasterXML jackson-databind 2.x (versions earlier than 2.9.9.2) has a polymorphic deserialization vulnerability when Default Typing is enabled and logback is present in the classpath. |
CVE-2020-26259 | XStream versions earlier than 1.4.15 have an arbitrary file deletion vulnerability during deserialization. Remote attackers may delete arbitrary known files on the host. |
CVE-2020-26945 | MyBatis versions earlier than 3.5.6 mishandle object stream deserialization. |
CVE-2020-5398 | In Spring WebFlux, when filenames are set based on user input in the Content-Disposition response header, a reflected file download (RFD) attack risk exists. |
CVE-2020-5398 | In Spring WebMVC, when filenames are set based on user input in the Content-Disposition response header, a reflected file download (RFD) attack risk exists. |
CVE-2021-20190 | jackson-databind versions earlier than 2.9.10.7 mishandle serialization gadgets and types, which may compromise data confidentiality, integrity, and availability. |
CVE-2021-44228 | Apache Log4j2 2.0-beta9 to 2.15.0 does not protect against attacker-controlled LDAP and other endpoints through the JNDI feature, allowing remote code execution (Log4Shell). |
CVE-2022-25845 | FastJSON versions earlier than 1.2.83 can bypass the autoType disable limit under specific conditions, leading to deserialization of untrusted data and allowing attacks on remote servers. |
CVE-2023-20860 | Spring Framework 6.0.0-6.0.6 or 5.3.0-5.3.25, when the ** pattern is used with mvcRequestMatcher in Spring Security configurations, may cause pattern matching inconsistencies and security bypasses. |
CVE-2023-23638 | Apache Dubbo has a deserialization vulnerability during generic invoke, which can lead to execution of malicious code. Affected versions include Dubbo 2.7.21 and earlier, 3.0.13 and earlier, and 3.1.5 and earlier. |
CVE-2023-24998 | Apache Commons FileUpload versions earlier than 1.5 do not limit the number of request parts processed, allowing attackers to trigger a denial of service through malicious uploads. |
CVE-2023-25194 | The Apache Kafka Connect API has a security vulnerability. An attacker with access to a Kafka Connect worker and the ability to create or modify connectors can achieve arbitrary code execution by configuring a JNDI login module. |
CVE-2023-29017 | vm2 sandbox versions earlier than 3.9.15 mishandle host objects in Error.prepareStackTrace when asynchronous errors are not handled, leading to sandbox escape and remote code execution. |
CVE-2023-30547 | vm2 sandbox versions 3.9.16 and earlier have an exception sanitization bypass in handleException(). Attackers can exploit unsanitized host exceptions to escape the sandbox and execute arbitrary code. |
CVE-2023-32314 | vm2 sandbox versions 3.9.17 and earlier have a sandbox escape vulnerability based on the Proxy specification that unexpectedly creates host objects, allowing remote code execution. |
CVE-2023-37466 | In vm2 versions 3.9.19 and earlier, Promise handler sanitization can be bypassed through the @@species accessor, allowing attackers to escape the sandbox and execute arbitrary code. The project is no longer maintained. |
CVE-2023-43804 | urllib3 may leak cookies to different origins when processing HTTP redirects if the Cookie header is explicitly set by the user. |
CVE-2023-47248 | PyArrow 0.14.0 to 14.0.0 has an untrusted data deserialization vulnerability in the IPC and Parquet readers, which can lead to arbitrary code execution. |
CVE-2024-22243 | Spring Web UriComponentsBuilder may have open redirect or SSRF attack risks when parsing externally provided URLs and validating the host. |
CVE-2024-22257 | Spring Security AuthenticatedVoter#vote may cause access control failures when a null Authentication parameter is passed. |
CVE-2024-22259 | Spring Web UriComponentsBuilder may have open redirect or SSRF attack risks when parsing externally provided URLs and validating the host (a variant of CVE-2024-22243). |
CVE-2024-31141 | The ConfigProvider plugin of the Apache Kafka client can be exploited by untrusted parties to read disk files or environment variables, which may lead to privilege escalation. |
CVE-2024-38809 | Spring Web applications may suffer a denial of service attack when parsing ETags in the If-Match or If-None-Match request headers. |
CVE-2024-38816 | The Spring WebMVC functional web framework has a path traversal attack risk when serving static resources through RouterFunctions using FileSystemResource. |
CVE-2024-38819 | The Spring WebFlux functional web framework has a path traversal attack risk when serving static resources, allowing attackers to obtain arbitrary files in the file system. |
CVE-2024-38819 | The Spring WebMVC functional web framework has a path traversal attack risk when serving static resources, allowing attackers to obtain arbitrary files in the file system. |