wiremock records
6 published records for vendor wiremock.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-39967No exploit | Full read and controlled SSRF through URL parameter when testing a request inside wiremock-studiowiremock · studio · CWE-918 | Critical10.0 | — | 1.0% | Sep 6, 2023 |
37Monitor | CVE-2018-9116No exploit | An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources andwiremock · wiremock · CWE-611 | Critical9.1 | — | 1.9% | Mar 29, 2018 |
26Monitor | CVE-2023-41329No exploit | Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studiowiremock · python wiremock · CWE-290 | Medium6.6 | — | 0.6% | Sep 6, 2023 |
24Monitor | CVE-2023-50069No exploit | WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature.wiremock · wiremock · CWE-79 | Medium6.1 | — | 0.4% | Dec 29, 2023 |
22Monitor | CVE-2018-9117No exploit | WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application dwiremock · wiremock · CWE-22 | Medium5.3 | — | 2.6% | Mar 29, 2018 |
21Monitor | CVE-2023-41327No exploit | Controlled SSRF through URL in the WireMockwiremock · studio · CWE-918 | Medium5.4 | — | 0.5% | Sep 6, 2023 |
- CVE-2023-3996740Plan
Full read and controlled SSRF through URL parameter when testing a request inside wiremock-studio
CriticalCVSS 10.0No exploitEPSS 1%wiremock · studioSep 6, 2023
- CVE-2018-911637Monitor
An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and
CriticalCVSS 9.1No exploitEPSS 2%wiremock · wiremockMar 29, 2018
- CVE-2023-4132926Monitor
Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio
MediumCVSS 6.6No exploitEPSS 1%wiremock · python wiremockSep 6, 2023
- CVE-2023-5006924Monitor
WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature.
MediumCVSS 6.1No exploitEPSS 0%wiremock · wiremockDec 29, 2023
- CVE-2018-911722Monitor
WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application d
MediumCVSS 5.3No exploitEPSS 3%wiremock · wiremockMar 29, 2018
- CVE-2023-4132721Monitor
Controlled SSRF through URL in the WireMock
MediumCVSS 5.4No exploitEPSS 0%wiremock · studioSep 6, 2023