getdbt kayıtları
getdbt üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-201 Insertion of Sensitive Information Into Sent Data1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2024-40637İstismar yok | Implicit override for built-in materializations from installed packages in dbt-coregetdbt · dbt core · CWE-74 | Yüksek7,8 | — | %0,4 | 16 Tem 2024 |
25İzleyin | CVE-2026-44968İstismar yok | dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parametersgetdbt · dbt mcp server · CWE-88 | Orta6,3 | — | %0,2 | 16 Tem 2026 |
17İzleyin | CVE-2026-44970İstismar yok | dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without Redactiongetdbt · dbt mcp server · CWE-201 | Orta4,3 | — | %0,4 | 16 Tem 2026 |
13İzleyin | CVE-2026-44969İstismar yok | dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabledgetdbt · dbt mcp server · CWE-532 | Düşük3,3 | — | %0,2 | 16 Tem 2026 |
8İzleyin | CVE-2026-29790İstismar yok | dbt-common: commonprefix() doesn't protect against path traversalgetdbt · dbt-common · CWE-22 | Düşük2,0 | — | %0,4 | 6 Mar 2026 |
- CVE-2024-4063731İzleyin
Implicit override for built-in materializations from installed packages in dbt-core
YüksekCVSS 7,8İstismar yokEPSS %0getdbt · dbt core16 Tem 2024
- CVE-2026-4496825İzleyin
dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
OrtaCVSS 6,3İstismar yokEPSS %0getdbt · dbt mcp server16 Tem 2026
- CVE-2026-4497017İzleyin
dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without Redaction
OrtaCVSS 4,3İstismar yokEPSS %0getdbt · dbt mcp server16 Tem 2026
- CVE-2026-4496913İzleyin
dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabled
DüşükCVSS 3,3İstismar yokEPSS %0getdbt · dbt mcp server16 Tem 2026
- CVE-2026-297908İzleyin
dbt-common: commonprefix() doesn't protect against path traversal
DüşükCVSS 2,0İstismar yokEPSS %0getdbt · dbt-common6 Mar 2026