biscuitsec records
3 published records for vendor biscuitsec.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1259 Improper Restriction of Security Token Assignment1
- CWE-269 Improper Privilege Management1
- CWE-347 Improper Verification of Cryptographic Signature1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-31053No exploit | Signature forgery in Biscuitbiscuitsec · biscuit-auth · CWE-347 | Critical9.8 | — | 1.0% | Jun 13, 2022 |
25Monitor | CVE-2024-41949No exploit | biscuit-rust vulnerable to public key confusion in third party blockbiscuitsec · biscuit-auth · CWE-269 | Medium6.4 | — | 0.2% | Aug 1, 2024 |
20Monitor | CVE-2024-41948No exploit | biscuit-java vulnerable to public key confusion in third party blockbiscuitsec · biscuit-java · CWE-1259 | Medium5.0 | — | 0.3% | Aug 1, 2024 |
- CVE-2022-3105339Monitor
Signature forgery in Biscuit
CriticalCVSS 9.8No exploitEPSS 1%biscuitsec · biscuit-authJun 13, 2022
- CVE-2024-4194925Monitor
biscuit-rust vulnerable to public key confusion in third party block
MediumCVSS 6.4No exploitEPSS 0%biscuitsec · biscuit-authAug 1, 2024
- CVE-2024-4194820Monitor
biscuit-java vulnerable to public key confusion in third party block
MediumCVSS 5.0No exploitEPSS 0%biscuitsec · biscuit-javaAug 1, 2024