mage records
6 published records for vendor mage.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-306 Missing Authentication for Critical Function1
- CWE-35 Path Traversal: '.../...//'1
- CWE-613 Insufficient Session Expiration1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-31143No exploit | Mage terminal user authentication not working properlymage · mage-ai · CWE-306 | Critical9.8 | — | 0.7% | May 9, 2023 |
35Monitor | CVE-2024-45187No exploit | Mage AI allows deleted users to use the terminal server with admin access, leading to remote code executionmage · mage-ai · CWE-613 | High8.8 | — | 0.5% | Aug 23, 2024 |
26Monitor | CVE-2024-45188No exploit | Mage AI file content request remote arbitrary file leakmage · mage-ai · CWE-22 | Medium6.5 | — | 0.9% | Aug 23, 2024 |
26Monitor | CVE-2024-45189No exploit | Mage AI git content request remote arbitrary file leakmage · mage-ai · CWE-22 | Medium6.5 | — | 0.9% | Aug 23, 2024 |
26Monitor | CVE-2024-45190No exploit | Mage AI pipeline interaction request remote arbitrary file leakmage · mage-ai · CWE-35 | Medium6.5 | — | 0.9% | Aug 23, 2024 |
21Monitor | CVE-2024-8072No exploit | Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary usersmage · mage-ai · CWE-200 | Medium5.3 | — | 0.6% | Aug 22, 2024 |
- CVE-2023-3114339Monitor
Mage terminal user authentication not working properly
CriticalCVSS 9.8No exploitEPSS 1%mage · mage-aiMay 9, 2023
- CVE-2024-4518735Monitor
Mage AI allows deleted users to use the terminal server with admin access, leading to remote code execution
HighCVSS 8.8No exploitEPSS 0%mage · mage-aiAug 23, 2024
- CVE-2024-4518826Monitor
Mage AI file content request remote arbitrary file leak
MediumCVSS 6.5No exploitEPSS 1%mage · mage-aiAug 23, 2024
- CVE-2024-4518926Monitor
Mage AI git content request remote arbitrary file leak
MediumCVSS 6.5No exploitEPSS 1%mage · mage-aiAug 23, 2024
- CVE-2024-4519026Monitor
Mage AI pipeline interaction request remote arbitrary file leak
MediumCVSS 6.5No exploitEPSS 1%mage · mage-aiAug 23, 2024
- CVE-2024-807221Monitor
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
MediumCVSS 5.3No exploitEPSS 1%mage · mage-aiAug 22, 2024