Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-23553 +1 in the same advisory: …23554 | Alpine is a scaffolding library in Java. Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2021-46853 | Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS. Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS. NVD description · AI analysis pending | 5.9 | <1% |
| — | ||
| CVE-2021-38370 | In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. NVD description · AI analysis pending | 5.9 | 2% | PoC |
| — | |
| CVE-2020-14929 | Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behav Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do. NVD description · AI analysis pending | 7.5 | 2% |
| — |