Записи mage
6 опубликованных записей вендора mage.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 16,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-306 Missing Authentication for Critical Function1
- CWE-35 Path Traversal: '.../...//'1
- CWE-613 Insufficient Session Expiration1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-31143Эксплойта нет | Mage terminal user authentication not working properlymage · mage-ai · CWE-306 | Критическая9,8 | — | 0,7 % | 9 мая 2023 г. |
35Наблюдать | CVE-2024-45187Эксплойта нет | Mage AI allows deleted users to use the terminal server with admin access, leading to remote code executionmage · mage-ai · CWE-613 | Высокая8,8 | — | 0,5 % | 23 авг. 2024 г. |
26Наблюдать | CVE-2024-45188Эксплойта нет | Mage AI file content request remote arbitrary file leakmage · mage-ai · CWE-22 | Средняя6,5 | — | 0,9 % | 23 авг. 2024 г. |
26Наблюдать | CVE-2024-45189Эксплойта нет | Mage AI git content request remote arbitrary file leakmage · mage-ai · CWE-22 | Средняя6,5 | — | 0,9 % | 23 авг. 2024 г. |
26Наблюдать | CVE-2024-45190Эксплойта нет | Mage AI pipeline interaction request remote arbitrary file leakmage · mage-ai · CWE-35 | Средняя6,5 | — | 0,9 % | 23 авг. 2024 г. |
21Наблюдать | CVE-2024-8072Эксплойта нет | Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary usersmage · mage-ai · CWE-200 | Средняя5,3 | — | 0,6 % | 22 авг. 2024 г. |
- CVE-2023-3114339Наблюдать
Mage terminal user authentication not working properly
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mage · mage-ai9 мая 2023 г.
- CVE-2024-4518735Наблюдать
Mage AI allows deleted users to use the terminal server with admin access, leading to remote code execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mage · mage-ai23 авг. 2024 г.
- CVE-2024-4518826Наблюдать
Mage AI file content request remote arbitrary file leak
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mage · mage-ai23 авг. 2024 г.
- CVE-2024-4518926Наблюдать
Mage AI git content request remote arbitrary file leak
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mage · mage-ai23 авг. 2024 г.
- CVE-2024-4519026Наблюдать
Mage AI pipeline interaction request remote arbitrary file leak
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mage · mage-ai23 авг. 2024 г.
- CVE-2024-807221Наблюдать
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
СредняяCVSS 5,3Эксплойта нетEPSS 1 %mage · mage-ai22 авг. 2024 г.