Записи webargs project
2 опубликованных записей вендора webargs project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
2 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2020-7965Эксплойта нет | flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input.webargs project · webargs · CWE-352 | Высокая8,8 | — | 0,6 % | 29 янв. 2020 г. |
32Наблюдать | CVE-2019-9710Эксплойта нет | An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products.webargs project · webargs · CWE-362 | Высокая8,1 | — | 1,1 % | 11 мар. 2019 г. |
- CVE-2020-796535Наблюдать
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webargs project · webargs29 янв. 2020 г.
- CVE-2019-971032Наблюдать
An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %webargs project · webargs11 мар. 2019 г.