Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jasperforge Subscribe
Filtered by product Jasperreports Server Community Project
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-1911 1 Jasperforge 1 Jasperreports Server Community Project 2017-08-16 6.8 MEDIUM N/A
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.