İçeriğe atla
Noroxi

Netflix kayıtları

netflix üreticisine ait 18 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

18 kayıt
  • CVE-2024-4701
    46Planlayın

    Path Traversal vulnerability via File Uploads in Genie

    KritikCVSS 9,9Kavram kanıtıEPSS %25

    netflix · genie14 May 2024

  • CVE-2022-27177
    40Planlayın

    A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to

    KritikCVSS 9,8İstismar yokEPSS %2

    netflix · consoleme1 Nis 2022

  • CVE-2020-9297
    40Planlayın

    Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators.

    KritikCVSS 9,8İstismar yokEPSS %2

    netflix · titus14 Tem 2020

  • CVE-2020-9296
    40Planlayın

    Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators.

    KritikCVSS 9,8İstismar yokEPSS %2

    netflix · conductor16 Haz 2020

  • CVE-2024-5023
    37İzleyin

    Arbitrary File Read Vulnerability in ConsoleMe via Limited Git command RCE

    KritikCVSS 9,3İstismar yokEPSS %1

    netflix · consoleme16 May 2024

  • CVE-2024-7093
    37İzleyin

    Server-Side Template Injection in Dispatch Message Templates

    KritikCVSS 9,4İstismar yokEPSS %1

    netflix · dispatch1 Ağu 2024

  • CVE-2024-9301
    34İzleyin

    A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a

    YüksekCVSS 8,7İstismar yokEPSS %1

    netflix · e2nest27 Eyl 2024

  • CVE-2015-7764
    30İzleyin

    Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.

    YüksekCVSS 7,5İstismar yokEPSS %2

    netflix · lemur9 Ağu 2017

  • CVE-2020-2322
    30İzleyin

    Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Re

    YüksekCVSS 7,5İstismar yokEPSS %1

    netflix · chaos monkey3 Ara 2020

  • CVE-2019-10028
    30İzleyin

    Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.

    YüksekCVSS 7,5İstismar yokEPSS %1

    netflix · dial reference21 Haz 2019

  • CVE-2023-40171
    30İzleyin

    Dispatch writes JWT tokens in error message

    YüksekCVSS 7,5İstismar yokEPSS %1

    netflix · dispatch17 Ağu 2023

  • CVE-2023-30797
    30İzleyin

    Insecure Random Generation in Netflix Lemur

    YüksekCVSS 7,5İstismar yokEPSS %1

    netflix · lemur19 Nis 2023

  • CVE-2020-9300
    26İzleyin

    The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themsel

    OrtaCVSS 6,5İstismar yokEPSS %1

    netflix · dispatch9 Kas 2020

  • CVE-2017-7266
    24İzleyin

    Netflix Security Monkey before 0.8.0 has an Open Redirect.

    OrtaCVSS 6,1İstismar yokEPSS %1

    netflix · security monkey26 Mar 2017

  • CVE-2021-28100
    22İzleyin

    Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--.

    OrtaCVSS 5,5İstismar yokEPSS %0

    netflix · priam23 Mar 2021

  • CVE-2020-2323
    21İzleyin

    Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read per

    OrtaCVSS 5,3İstismar yokEPSS %1

    netflix · chaos monkey3 Ara 2020

  • CVE-2020-9299
    21İzleyin

    There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Pr

    OrtaCVSS 5,4İstismar yokEPSS %1

    netflix · dispatch9 Kas 2020

  • CVE-2021-28099
    17İzleyin

    In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories w

    OrtaCVSS 4,4İstismar yokEPSS %0

    netflix · hollow23 Mar 2021