Записи projectcontour
5 опубликованных записей вендора projectcontour.
Профиль для исследователя
- Попали в KEV
- 1 · 20 %
- С эксплойтом
- 1 · 20 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 80 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-277 Insecure Inherited Permissions1
- CWE-306 Missing Authentication for Critical Function1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
39Наблюдать | CVE-2024-36539Proof of concept | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account'sprojectcontour · contour · CWE-277 | Критическая9,8 | — | 1,3 % | 24 июл. 2024 г. |
34Наблюдать | CVE-2021-32783Эксплойта нет | Authorization bypass in Contourprojectcontour · contour · CWE-441 | Высокая8,5 | — | 1,2 % | 23 июл. 2021 г. |
32Наблюдать | CVE-2026-41246Эксплойта нет | Contour: Lua code injection via Cookie Path Rewrite Policyprojectcontour · contour · CWE-94 | Высокая8,1 | — | 0,8 % | 23 апр. 2026 г. |
30Наблюдать | CVE-2020-15127Эксплойта нет | Denial of service in Contourprojectcontour · contour · CWE-306 | Высокая7,5 | — | 1,4 % | 5 авг. 2020 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2024-3653939Наблюдать
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's
КритическаяCVSS 9,8Proof of conceptEPSS 1 %projectcontour · contour24 июл. 2024 г.
- CVE-2021-3278334Наблюдать
Authorization bypass in Contour
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %projectcontour · contour23 июл. 2021 г.
- CVE-2026-4124632Наблюдать
Contour: Lua code injection via Cookie Path Rewrite Policy
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %projectcontour · contour23 апр. 2026 г.
- CVE-2020-1512730Наблюдать
Denial of service in Contour
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %projectcontour · contour5 авг. 2020 г.