perfsonar records
8 published records for vendor perfsonar.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-73 External Control of File Name or Path1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-41412Proof of concept | An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Requperfsonar · perfsonar · CWE-918 | High8.6 | — | 4.5% | Nov 30, 2022 |
23Monitor | CVE-2018-12523Proof of concept | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2.perfsonar · monitoring and debugging dashboard · CWE-200 | Medium5.3 | — | 7.1% | Jun 18, 2018 |
23Monitor | CVE-2018-12524Proof of concept | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2.perfsonar · monitoring and debugging dashboard · CWE-200 | Medium5.3 | — | 7.1% | Jun 18, 2018 |
23Monitor | CVE-2018-12525Proof of concept | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2.perfsonar · monitoring and debugging dashboard · CWE-200 | Medium5.3 | — | 7.1% | Jun 18, 2018 |
23Monitor | CVE-2018-12522Proof of concept | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2.perfsonar · monitoring and debugging dashboard · CWE-200 | Medium5.3 | — | 7.1% | Jun 18, 2018 |
21Monitor | CVE-2022-45213No exploit | perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.perfsonar · perfsonar · CWE-73 | Medium5.3 | — | 0.6% | Jan 1, 2023 |
21Monitor | CVE-2022-45027No exploit | perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.perfsonar · perfsonar · CWE-918 | Medium5.3 | — | 0.6% | Jan 1, 2023 |
18Monitor | CVE-2022-41413Proof of concept | perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted iperfsonar · perfsonar · CWE-352 | Medium4.3 | — | 2.1% | Nov 30, 2022 |
- CVE-2022-4141235Monitor
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Requ
HighCVSS 8.6Proof of conceptEPSS 4%perfsonar · perfsonarNov 30, 2022
- CVE-2018-1252323Monitor
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2.
MediumCVSS 5.3Proof of conceptEPSS 7%perfsonar · monitoring and debugging dashboardJun 18, 2018
- CVE-2018-1252423Monitor
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2.
MediumCVSS 5.3Proof of conceptEPSS 7%perfsonar · monitoring and debugging dashboardJun 18, 2018
- CVE-2018-1252523Monitor
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2.
MediumCVSS 5.3Proof of conceptEPSS 7%perfsonar · monitoring and debugging dashboardJun 18, 2018
- CVE-2018-1252223Monitor
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2.
MediumCVSS 5.3Proof of conceptEPSS 7%perfsonar · monitoring and debugging dashboardJun 18, 2018
- CVE-2022-4521321Monitor
perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.
MediumCVSS 5.3No exploitEPSS 1%perfsonar · perfsonarJan 1, 2023
- CVE-2022-4502721Monitor
perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.
MediumCVSS 5.3No exploitEPSS 1%perfsonar · perfsonarJan 1, 2023
- CVE-2022-4141318Monitor
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted i
MediumCVSS 4.3Proof of conceptEPSS 2%perfsonar · perfsonarNov 30, 2022