contribsys kayıtları
contribsys üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-1892Kavram kanıtı | Cross-site Scripting (XSS) - Reflected in sidekiq/sidekiqcontribsys · sidekiq · CWE-79 | Kritik9,6 | — | %2,7 | 21 Nis 2023 |
32İzleyin | CVE-2022-23837İstismar yok | In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph.contribsys · sidekiq · CWE-770 | Yüksek7,5 | — | %5,2 | 21 Oca 2022 |
30İzleyin | CVE-2023-37279İstismar yok | Faktory Web Dashboard can lead to denial of service(DOS) via malicious user inputcontribsys · faktory · CWE-770 | Yüksek7,5 | — | %0,9 | 20 Eyl 2023 |
25İzleyin | CVE-2021-30151Kavram kanıtı | Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.contribsys · sidekiq · CWE-79 | Orta6,1 | — | %4,2 | 6 Nis 2021 |
24İzleyin | CVE-2023-46950İstismar yok | Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL contribsys · sidekiq · CWE-79 | Orta6,1 | — | %0,6 | 1 Mar 2024 |
24İzleyin | CVE-2023-46951İstismar yok | Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted paylcontribsys · sidekiq · CWE-79 | Orta6,1 | — | %0,5 | 1 Mar 2024 |
19İzleyin | CVE-2023-26141İstismar yok | Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.jscontribsys · sidekiq · CWE-400 | Orta4,9 | — | %0,9 | 14 Eyl 2023 |
- CVE-2023-189239İzleyin
Cross-site Scripting (XSS) - Reflected in sidekiq/sidekiq
KritikCVSS 9,6Kavram kanıtıEPSS %3contribsys · sidekiq21 Nis 2023
- CVE-2022-2383732İzleyin
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph.
YüksekCVSS 7,5İstismar yokEPSS %5contribsys · sidekiq21 Oca 2022
- CVE-2023-3727930İzleyin
Faktory Web Dashboard can lead to denial of service(DOS) via malicious user input
YüksekCVSS 7,5İstismar yokEPSS %1contribsys · faktory20 Eyl 2023
- CVE-2021-3015125İzleyin
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
OrtaCVSS 6,1Kavram kanıtıEPSS %4contribsys · sidekiq6 Nis 2021
- CVE-2023-4695024İzleyin
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL
OrtaCVSS 6,1İstismar yokEPSS %1contribsys · sidekiq1 Mar 2024
- CVE-2023-4695124İzleyin
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payl
OrtaCVSS 6,1İstismar yokEPSS %1contribsys · sidekiq1 Mar 2024
- CVE-2023-2614119İzleyin
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js
OrtaCVSS 4,9İstismar yokEPSS %1contribsys · sidekiq14 Eyl 2023