sandstorm kayıtları
sandstorm üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-6199İstismar yok | A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.sandstorm · sandstorm · CWE-287 | Kritik9,8 | — | %3,0 | 6 Şub 2018 |
33İzleyin | CVE-2017-6201İstismar yok | A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203.sandstorm · sandstorm · CWE-918 | Yüksek8,1 | — | %1,9 | 6 Şub 2018 |
27İzleyin | CVE-2017-6200İstismar yok | Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function.sandstorm · sandstorm · CWE-200 | Orta6,5 | — | %2,3 | 6 Şub 2018 |
26İzleyin | CVE-2017-6198İstismar yok | The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process.sandstorm · sandstorm · CWE-400 | Orta6,5 | — | %1,4 | 6 Şub 2018 |
- CVE-2017-619940Planlayın
A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.
KritikCVSS 9,8İstismar yokEPSS %3sandstorm · sandstorm6 Şub 2018
- CVE-2017-620133İzleyin
A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203.
YüksekCVSS 8,1İstismar yokEPSS %2sandstorm · sandstorm6 Şub 2018
- CVE-2017-620027İzleyin
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function.
OrtaCVSS 6,5İstismar yokEPSS %2sandstorm · sandstorm6 Şub 2018
- CVE-2017-619826İzleyin
The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process.
OrtaCVSS 6,5İstismar yokEPSS %1sandstorm · sandstorm6 Şub 2018