projectcontour records
5 published records for vendor projectcontour.
Researcher profile
- Entered KEV
- 1 · 20%
- Weaponized
- 1 · 20%
- Pre-auth RCE
- 0
- With a fix record
- 80%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-277 Insecure Inherited Permissions1
- CWE-306 Missing Authentication for Critical Function1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
39Monitor | CVE-2024-36539Proof of concept | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account'sprojectcontour · contour · CWE-277 | Critical9.8 | — | 1.3% | Jul 24, 2024 |
34Monitor | CVE-2021-32783No exploit | Authorization bypass in Contourprojectcontour · contour · CWE-441 | High8.5 | — | 1.2% | Jul 23, 2021 |
32Monitor | CVE-2026-41246No exploit | Contour: Lua code injection via Cookie Path Rewrite Policyprojectcontour · contour · CWE-94 | High8.1 | — | 0.8% | Apr 23, 2026 |
30Monitor | CVE-2020-15127No exploit | Denial of service in Contourprojectcontour · contour · CWE-306 | High7.5 | — | 1.4% | Aug 5, 2020 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2024-3653939Monitor
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's
CriticalCVSS 9.8Proof of conceptEPSS 1%projectcontour · contourJul 24, 2024
- CVE-2021-3278334Monitor
Authorization bypass in Contour
HighCVSS 8.5No exploitEPSS 1%projectcontour · contourJul 23, 2021
- CVE-2026-4124632Monitor
Contour: Lua code injection via Cookie Path Rewrite Policy
HighCVSS 8.1No exploitEPSS 1%projectcontour · contourApr 23, 2026
- CVE-2020-1512730Monitor
Denial of service in Contour
HighCVSS 7.5No exploitEPSS 1%projectcontour · contourAug 5, 2020