Known vulnerabilities in Retrofit

Vendor: Square
Software: Retrofit
Software CPE: cpe:2.3:a:square_open_source:retrofit:*:*:*:*:*:*:*:*
Total vulnerabilities: 2
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 6.9

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Retrofit Retrofit is affected by 2 known vulnerabilities: 2 medium Critical High Medium Low

Vulnerabilities (2)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU22874 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2018-1000844
CWE-611 Medium
No
No
2.6.0 20.11.2019 SB2018122019
#VU22873 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-1000850
CWE-22 Medium
No
No
2.0.0, 2.0.1, 2.0.2, 2.1.0, 2.2.0, 2.3.0, 2.4.0 20.11.2019 SB2018122018
SB2019112016
SB2025081409