maven package report

Is org.folio:mod-data-export-spring safe?

1 known vulnerability, worst severity CRITICAL.

cvss
9.1

how bad it is if exploited, out of 10

epss
0.70%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-vf78-3q9f-92g3, the advisory selected below

// advisories

GHSA-vf78-3q9f-92g3

CRITICALCVE-2024-23687

The module creates a system user that is used to perform internal module-to-module operations. Credentials for this user are hard-coded in the source code. This makes it trivial to authenticate as this user, resulting in unauthorized access to potentially dangerous APIs, allowing to view and modify configuration including single-sign-on configuration, to read, add and modify user data, and to re

Affected
>= 2.0.0, < 2.0.2
Fixed in
2.0.2
Weakness
CWE-798
Published
2023-07-25
Source
github

GHSANVDMITREreferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 03:31 UTC. The most recent advisory here was published 2023-07-25. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.folio:mod-data-export-spring safe? maven package security report | CyberXYZ