yeti-platform kayıtları
yeti-platform üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-798 Use of Hard-coded Credentials1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2024-46507Kavram kanıtı | A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attayeti-platform · yeti · CWE-94 | Yüksek7,3 | — | %3,9 | 8 May 2026 |
30İzleyin | CVE-2024-45412İstismar yok | Yeti affected by a Potential Denial of Service due to the One Milion Unicode characters attackyeti-platform · yeti · CWE-770 | Yüksek7,5 | — | %0,8 | 10 Eyl 2024 |
30İzleyin | CVE-2024-46508İstismar yok | yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEYyeti-platform · yeti · CWE-798 | Yüksek7,5 | — | %0,4 | 8 May 2026 |
- CVE-2024-4650730İzleyin
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows atta
YüksekCVSS 7,3Kavram kanıtıEPSS %4yeti-platform · yeti8 May 2026
- CVE-2024-4541230İzleyin
Yeti affected by a Potential Denial of Service due to the One Milion Unicode characters attack
YüksekCVSS 7,5İstismar yokEPSS %1yeti-platform · yeti10 Eyl 2024
- CVE-2024-4650830İzleyin
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY
YüksekCVSS 7,5İstismar yokEPSS %0yeti-platform · yeti8 May 2026