cratedb records
3 published records for vendor cratedb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-51982No exploit | CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component.cratedb · cratedb · CWE-287 | Critical9.8 | — | 0.7% | Jan 29, 2024 |
27Monitor | CVE-2024-24565Proof of concept | CrateDB database has an arbitrary file read vulnerabilitycratedb · cratedb · CWE-22 | Medium6.5 | — | 3.1% | Jan 30, 2024 |
21Monitor | CVE-2024-37309No exploit | Client initialized Session-Renegotiation DoScratedb · cratedb · CWE-770 | Medium5.3 | — | 0.7% | Jun 13, 2024 |
- CVE-2023-5198239Monitor
CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component.
CriticalCVSS 9.8No exploitEPSS 1%cratedb · cratedbJan 29, 2024
- CVE-2024-2456527Monitor
CrateDB database has an arbitrary file read vulnerability
MediumCVSS 6.5Proof of conceptEPSS 3%cratedb · cratedbJan 30, 2024
- CVE-2024-3730921Monitor
Client initialized Session-Renegotiation DoS
MediumCVSS 5.3No exploitEPSS 1%cratedb · cratedbJun 13, 2024