webargs project kayıtları
webargs project üreticisine ait 2 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
2 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2020-7965İstismar yok | flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input.webargs project · webargs · CWE-352 | Yüksek8,8 | — | %0,6 | 29 Oca 2020 |
32İzleyin | CVE-2019-9710İstismar yok | An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products.webargs project · webargs · CWE-362 | Yüksek8,1 | — | %1,1 | 11 Mar 2019 |
- CVE-2020-796535İzleyin
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input.
YüksekCVSS 8,8İstismar yokEPSS %1webargs project · webargs29 Oca 2020
- CVE-2019-971032İzleyin
An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products.
YüksekCVSS 8,1İstismar yokEPSS %1webargs project · webargs11 Mar 2019