CocoaPods kayıtları
cocoapods üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %40
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-488 Exposure of Data Element to Wrong Session1
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2024-38366Kavram kanıtı | CoacoaPods trunk RCE in email verification system rfc-822cocoapods · trunk.cocoapods.org · CWE-74 | Kritik10,0 | — | %17,8 | 1 Tem 2024 |
41Planlayın | CVE-2024-38368İstismar yok | Trunk's 'Claim your pod' could be used to obtain un-used podscocoapods · trunk.cocoapods.org · CWE-668 | Kritik9,3 | — | %14,9 | 1 Tem 2024 |
41Planlayın | CVE-2024-38367İstismar yok | CoacoaPods trunk sessions verification step could be manipulated for owner session hijackingcocoapods · trunk.cocoapods.org · CWE-488 | Kritik9,6 | — | %11,1 | 1 Tem 2024 |
40Planlayın | CVE-2022-24440İstismar yok | The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection.cocoapods · cocoapods-downloader · CWE-88 | Kritik9,8 | — | %2,5 | 1 Nis 2022 |
40Planlayın | CVE-2022-21223İstismar yok | The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection.cocoapods · cocoapods-downloader · CWE-88 | Kritik9,8 | — | %1,7 | 1 Nis 2022 |
- CVE-2024-3836645Planlayın
CoacoaPods trunk RCE in email verification system rfc-822
KritikCVSS 10,0Kavram kanıtıEPSS %18cocoapods · trunk.cocoapods.org1 Tem 2024
- CVE-2024-3836841Planlayın
Trunk's 'Claim your pod' could be used to obtain un-used pods
KritikCVSS 9,3İstismar yokEPSS %15cocoapods · trunk.cocoapods.org1 Tem 2024
- CVE-2024-3836741Planlayın
CoacoaPods trunk sessions verification step could be manipulated for owner session hijacking
KritikCVSS 9,6İstismar yokEPSS %11cocoapods · trunk.cocoapods.org1 Tem 2024
- CVE-2022-2444040Planlayın
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection.
KritikCVSS 9,8İstismar yokEPSS %3cocoapods · cocoapods-downloader1 Nis 2022
- CVE-2022-2122340Planlayın
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection.
KritikCVSS 9,8İstismar yokEPSS %2cocoapods · cocoapods-downloader1 Nis 2022