Записи wiremock
6 опубликованных записей вендора wiremock.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 33,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2023-39967Эксплойта нет | Full read and controlled SSRF through URL parameter when testing a request inside wiremock-studiowiremock · studio · CWE-918 | Критическая10,0 | — | 1,0 % | 6 сент. 2023 г. |
37Наблюдать | CVE-2018-9116Эксплойта нет | An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources andwiremock · wiremock · CWE-611 | Критическая9,1 | — | 1,9 % | 29 мар. 2018 г. |
26Наблюдать | CVE-2023-41329Эксплойта нет | Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studiowiremock · python wiremock · CWE-290 | Средняя6,6 | — | 0,6 % | 6 сент. 2023 г. |
24Наблюдать | CVE-2023-50069Эксплойта нет | WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature.wiremock · wiremock · CWE-79 | Средняя6,1 | — | 0,4 % | 29 дек. 2023 г. |
22Наблюдать | CVE-2018-9117Эксплойта нет | WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application dwiremock · wiremock · CWE-22 | Средняя5,3 | — | 2,6 % | 29 мар. 2018 г. |
21Наблюдать | CVE-2023-41327Эксплойта нет | Controlled SSRF through URL in the WireMockwiremock · studio · CWE-918 | Средняя5,4 | — | 0,5 % | 6 сент. 2023 г. |
- CVE-2023-3996740В плане
Full read and controlled SSRF through URL parameter when testing a request inside wiremock-studio
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %wiremock · studio6 сент. 2023 г.
- CVE-2018-911637Наблюдать
An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %wiremock · wiremock29 мар. 2018 г.
- CVE-2023-4132926Наблюдать
Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio
СредняяCVSS 6,6Эксплойта нетEPSS 1 %wiremock · python wiremock6 сент. 2023 г.
- CVE-2023-5006924Наблюдать
WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wiremock · wiremock29 дек. 2023 г.
- CVE-2018-911722Наблюдать
WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application d
СредняяCVSS 5,3Эксплойта нетEPSS 3 %wiremock · wiremock29 мар. 2018 г.
- CVE-2023-4132721Наблюдать
Controlled SSRF through URL in the WireMock
СредняяCVSS 5,4Эксплойта нетEPSS 0 %wiremock · studio6 сент. 2023 г.