Skip to content
Noroxi

ethyca records

20 published records for vendor ethyca.

All records

20 records
  • Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    ethyca · fidesJul 2, 2024

  • Cryptographically Weak Generation of One-Time Codes for Identity Verification in ethyca-fides

    CriticalCVSS 9.1No exploitEPSS 1%

    ethyca · fidesNov 15, 2023

  • Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation

    HighCVSS 8.6No exploitEPSS 0%

    ethyca · fidesSep 8, 2025

  • Fides vulnerable to Path Traversal in Webserver API

    HighCVSS 7.5No exploitEPSS 1%

    ethyca · fidesJul 5, 2023

  • Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine

    HighCVSS 7.2No exploitEPSS 1%

    ethyca · fidesSep 4, 2024

  • Remote Code Execution in Custom Integration Upload in Fides

    HighCVSS 7.2No exploitEPSS 1%

    ethyca · fidesSep 6, 2023

  • Server-Side Request Forgery Vulnerability in Custom Integration Upload

    HighCVSS 7.2No exploitEPSS 1%

    ethyca · fidesOct 25, 2023

  • Fides Information Disclosure Vulnerability in Config API Endpoint

    MediumCVSS 6.5No exploitEPSS 1%

    ethyca · fidesOct 25, 2023

  • Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints in Fides

    MediumCVSS 6.5No exploitEPSS 1%

    ethyca · fidesMay 30, 2024

  • Fides Webserver API Rate Limiting Vulnerability in Proxied Environments

    MediumCVSS 6.3No exploitEPSS 0%

    ethyca · fidesSep 8, 2025

  • Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

    MediumCVSS 6.1No exploitEPSS 1%

    ethyca · fidesNov 8, 2023

  • Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

    MediumCVSS 5.3Proof of conceptEPSS 1%

    ethyca · fidesJul 3, 2024

  • Fides JavaScript Injection Vulnerability in Privacy Center URL

    MediumCVSS 5.4No exploitEPSS 1%

    ethyca · fidesOct 25, 2023

  • Fides Webserver Authentication Timing-Based Username Enumeration Vulnerability

    MediumCVSS 5.3No exploitEPSS 1%

    ethyca · fidesSep 4, 2024

  • Fides Webserver Vulnerable to SVG Bomb File Uploads

    MediumCVSS 4.9No exploitEPSS 1%

    ethyca · fidesJul 18, 2023

  • Fides Webserver Vulnerable to Zip Bomb File Uploads

    MediumCVSS 4.9No exploitEPSS 1%

    ethyca · fidesJul 18, 2023

  • Partial Password Exposure Vulnerability in Fides Webserver Logs

    LowCVSS 3.3No exploitEPSS 0%

    ethyca · fidesMay 29, 2024

  • Password Policy Bypass Vulnerability in Fides Webserver

    LowCVSS 2.0No exploitEPSS 1%

    ethyca · fidesNov 26, 2024

  • Fides's Admin UI User Password Change Does Not Invalidate Current Session

    LowCVSS 1.7No exploitEPSS 0%

    ethyca · fidesSep 8, 2025

  • Fides Lacks Brute-Force Protections on Authentication Endpoints

    LowCVSS 1.7No exploitEPSS 0%

    ethyca · fidesSep 8, 2025