maven package report

Is org.bedework:bw-webdav safe?

1 known vulnerability, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
1.5%

chance of exploitation in the next 30 days

xyz score
3.4

CyberXYZ composite, out of 10

fig. 01 — GHSA-5p52-j8pw-j7x5, the advisory selected below

// advisories

GHSA-5p52-j8pw-j7x5

HIGHCVE-2018-20000

Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.

Affected
>= 4.0.1, < 4.0.3
Fixed in
4.0.3
Weakness
CWE-611
Published
2018-12-19
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:55 UTC. The most recent advisory here was published 2018-12-19. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.bedework:bw-webdav safe? maven package security report | CyberXYZ