OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulne
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, bu
Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter
Improper neutralization of special elements used in an expression language statement ('expression language injection') v
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the p
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configurat
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co
Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 thro
Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed e
n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authentic
A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acrofor
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@pa
OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs du
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (app
An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allo
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider
Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Env
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as J
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carr
A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a rep
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v
Frequently Asked Questions
What is CWE-917?
CWE-917 (CWE-917) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-917?
There are 35 CVE records associated with CWE-917 in our database. Of these, 12 are critical severity, 17 are high severity, and 3 are medium severity.
How can I protect against CWE-917 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-917 using AI-powered security agents.
Detect CWE-917 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-917 vulnerabilities across your infrastructure.
Get Started