StackStorm records
6 published records for vendor stackstorm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2021-44657No exploit | In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commandsstackstorm · stackstorm | High8.8 | — | 2.5% | Dec 15, 2021 |
31Monitor | CVE-2021-28667No exploit | StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space.stackstorm · stackstorm · CWE-835 | High7.5 | — | 2.2% | Mar 17, 2021 |
30Monitor | CVE-2022-44009No exploit | Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to astackstorm · stackstorm · CWE-862 | High7.5 | — | 0.6% | Dec 5, 2022 |
25Monitor | CVE-2019-9580Proof of concept | In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" orstackstorm · stackstorm · CWE-79 | Medium6.1 | — | 3.0% | Mar 9, 2019 |
21Monitor | CVE-2018-20345No exploit | Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackSstackstorm · stackstorm | Medium5.3 | — | 0.7% | Dec 21, 2018 |
21Monitor | CVE-2022-43706No exploit | Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pastackstorm · stackstorm · CWE-79 | Medium5.4 | — | 0.4% | Dec 5, 2022 |
- CVE-2021-4465736Monitor
In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands
HighCVSS 8.8No exploitEPSS 2%stackstorm · stackstormDec 15, 2021
- CVE-2021-2866731Monitor
StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space.
HighCVSS 7.5No exploitEPSS 2%stackstorm · stackstormMar 17, 2021
- CVE-2022-4400930Monitor
Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to a
HighCVSS 7.5No exploitEPSS 1%stackstorm · stackstormDec 5, 2022
- CVE-2019-958025Monitor
In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" or
MediumCVSS 6.1Proof of conceptEPSS 3%stackstorm · stackstormMar 9, 2019
- CVE-2018-2034521Monitor
Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackS
MediumCVSS 5.3No exploitEPSS 1%stackstorm · stackstormDec 21, 2018
- CVE-2022-4370621Monitor
Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pa
MediumCVSS 5.4No exploitEPSS 0%stackstorm · stackstormDec 5, 2022