Dropwizard is a lightweight Java framework for building RESTful web services and microservices, with its documented vulnerability exposure centered on the validation module and injection-class weaknesses in data handling and output sanitization. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dropwizard over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11002HIGH dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature ena | Apr 10, 2020 | 8.8 | 24 | NO | NO |
CVE-2020-5245HIGH Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary | Feb 24, 2020 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dropwizard.
Media articles that mention a CVE ID that affects a product developed by Dropwizard — matched by CVE ID, not by vendor name.