Skip to content
Noroxi

StackStorm records

6 published records for vendor stackstorm.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
16.7%
Median publish → KEV
No record has entered KEV

All records

6 records
  • In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands

    HighCVSS 8.8No exploitEPSS 2%

    stackstorm · stackstormDec 15, 2021

  • StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space.

    HighCVSS 7.5No exploitEPSS 2%

    stackstorm · stackstormMar 17, 2021

  • Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to a

    HighCVSS 7.5No exploitEPSS 1%

    stackstorm · stackstormDec 5, 2022

  • CVE-2019-9580
    25Monitor

    In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" or

    MediumCVSS 6.1Proof of conceptEPSS 3%

    stackstorm · stackstormMar 9, 2019

  • Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackS

    MediumCVSS 5.3No exploitEPSS 1%

    stackstorm · stackstormDec 21, 2018

  • Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pa

    MediumCVSS 5.4No exploitEPSS 0%

    stackstorm · stackstormDec 5, 2022