Graphite project kayıtları
graphite project üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %14,3
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-707 Improper Neutralization3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2013-5093Silahlaştırılmış | The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, whigraphite project · graphite · CWE-94 | Orta6,8 | — | %38,7 | 27 Eyl 2013 |
35İzleyin | CVE-2017-18638Kavram kanıtı | send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF.graphite project · graphite · CWE-918 | Yüksek7,5 | — | %15,3 | 11 Eki 2019 |
28İzleyin | CVE-2013-5942İstismar yok | Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted graphite project · graphite · CWE-94 | Orta6,8 | — | %2,1 | 27 Eyl 2013 |
21İzleyin | CVE-2022-4728İstismar yok | Graphite Web Cookie cross site scriptinggraphite project · graphite · CWE-707 | Orta5,4 | — | %0,8 | 27 Ara 2022 |
21İzleyin | CVE-2022-4730İstismar yok | Graphite Web Absolute Time Range cross site scriptinggraphite project · graphite · CWE-707 | Orta5,4 | — | %0,8 | 27 Ara 2022 |
21İzleyin | CVE-2022-4729İstismar yok | Graphite Web Template Name cross site scriptinggraphite project · graphite · CWE-707 | Orta5,4 | — | %0,7 | 27 Ara 2022 |
18İzleyin | CVE-2013-5943İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML graphite project · graphite · CWE-79 | Orta4,3 | — | %1,8 | 27 Eyl 2013 |
- CVE-2013-509339İzleyin
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, whi
OrtaCVSS 6,8SilahlaştırılmışEPSS %39graphite project · graphite27 Eyl 2013
- CVE-2017-1863835İzleyin
send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF.
YüksekCVSS 7,5Kavram kanıtıEPSS %15graphite project · graphite11 Eki 2019
- CVE-2013-594228İzleyin
Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted
OrtaCVSS 6,8İstismar yokEPSS %2graphite project · graphite27 Eyl 2013
- CVE-2022-472821İzleyin
Graphite Web Cookie cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1graphite project · graphite27 Ara 2022
- CVE-2022-473021İzleyin
Graphite Web Absolute Time Range cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1graphite project · graphite27 Ara 2022
- CVE-2022-472921İzleyin
Graphite Web Template Name cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1graphite project · graphite27 Ara 2022
- CVE-2013-594318İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3İstismar yokEPSS %2graphite project · graphite27 Eyl 2013