Business Application Platform (BAP)
95%
Total Score
85
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2023-45824 oro/platform is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.1.0 - 5.1.3, 5.0.0 - 5.0.12 and 4.2.0 - 4.2.10. | 4.2.0 - 4.2.105.0.0 - 5.0.125.1.0 - 5.1.3 | Medium |
CVE-2022-41951 oro/platform is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 4.1.0 - 4.1.13, 4.2.0 - 4.2.10 and 5.0.0 - 5.0.8. | 4.1.0 - 4.1.134.2.0 - 4.2.105.0.0 - 5.0.8 | High |
CVE-2021-43852 oro/platform is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 4.1.0 - 4.1.14 and 4.2.0 - 4.2.8. | 4.1.0 - 4.1.144.2.0 - 4.2.8 | Medium |
CVE-2021-41236 oro/platform is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.1.0 - 3.1.21, 4.1.0 - 4.1.14 and 4.2.0 - 4.2.8. | 3.1.0 - 3.1.214.1.0 - 4.1.144.2.0 - 4.2.8 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 2.0.* | — | — |
twig/twig Version ~v3.21.1 | — | — |
brick/math Version ~0.11.0 | — | — |
doctrine/orm Version ~2.20.6 | — | — |
symfony/flex Version 2.10.* | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant