mage kayıtları
mage üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %16,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-306 Missing Authentication for Critical Function1
- CWE-35 Path Traversal: '.../...//'1
- CWE-613 Insufficient Session Expiration1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-31143İstismar yok | Mage terminal user authentication not working properlymage · mage-ai · CWE-306 | Kritik9,8 | — | %0,7 | 9 May 2023 |
35İzleyin | CVE-2024-45187İstismar yok | Mage AI allows deleted users to use the terminal server with admin access, leading to remote code executionmage · mage-ai · CWE-613 | Yüksek8,8 | — | %0,5 | 23 Ağu 2024 |
26İzleyin | CVE-2024-45188İstismar yok | Mage AI file content request remote arbitrary file leakmage · mage-ai · CWE-22 | Orta6,5 | — | %0,9 | 23 Ağu 2024 |
26İzleyin | CVE-2024-45189İstismar yok | Mage AI git content request remote arbitrary file leakmage · mage-ai · CWE-22 | Orta6,5 | — | %0,9 | 23 Ağu 2024 |
26İzleyin | CVE-2024-45190İstismar yok | Mage AI pipeline interaction request remote arbitrary file leakmage · mage-ai · CWE-35 | Orta6,5 | — | %0,9 | 23 Ağu 2024 |
21İzleyin | CVE-2024-8072İstismar yok | Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary usersmage · mage-ai · CWE-200 | Orta5,3 | — | %0,6 | 22 Ağu 2024 |
- CVE-2023-3114339İzleyin
Mage terminal user authentication not working properly
KritikCVSS 9,8İstismar yokEPSS %1mage · mage-ai9 May 2023
- CVE-2024-4518735İzleyin
Mage AI allows deleted users to use the terminal server with admin access, leading to remote code execution
YüksekCVSS 8,8İstismar yokEPSS %0mage · mage-ai23 Ağu 2024
- CVE-2024-4518826İzleyin
Mage AI file content request remote arbitrary file leak
OrtaCVSS 6,5İstismar yokEPSS %1mage · mage-ai23 Ağu 2024
- CVE-2024-4518926İzleyin
Mage AI git content request remote arbitrary file leak
OrtaCVSS 6,5İstismar yokEPSS %1mage · mage-ai23 Ağu 2024
- CVE-2024-4519026İzleyin
Mage AI pipeline interaction request remote arbitrary file leak
OrtaCVSS 6,5İstismar yokEPSS %1mage · mage-ai23 Ağu 2024
- CVE-2024-807221İzleyin
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
OrtaCVSS 5,3İstismar yokEPSS %1mage · mage-ai22 Ağu 2024