maven package report

Is eu.hinsch:spring-boot-actuator-logview safe?

1 known vulnerability, worst severity HIGH.

cvss
7.7

how bad it is if exploited, out of 10

epss
21.0%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-p4q6-qxjx-8jgp, the advisory selected below

// advisories

GHSA-p4q6-qxjx-8jgp

HIGHCVE-2021-21234

The nature of this library is to expose a log file directory via admin (spring boot actuator) HTTP endpoints. Both the filename to view and a base folder (relative to the logging folder root) can be specified via request parameters. While the filename parameter was checked to prevent directory traversal exploits (so that filename=../somefile would not work), the base folder parameter was not suffi

Affected
< 0.2.13
Fixed in
0.2.13
Weakness
CWE-22
Published
2021-01-05
Source
github

GHSANVDMITREreferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 00:53 UTC. The most recent advisory here was published 2021-01-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is eu.hinsch:spring-boot-actuator-logview safe? maven package security report | CyberXYZ