Netflix kayıtları
netflix üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %61,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-330 Use of Insufficiently Random Values2
- CWE-862 Missing Authorization2
- CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2024-4701Kavram kanıtı | Path Traversal vulnerability via File Uploads in Genienetflix · genie · CWE-22 | Kritik9,9 | — | %24,6 | 14 May 2024 |
40Planlayın | CVE-2022-27177İstismar yok | A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to netflix · consoleme · CWE-134 | Kritik9,8 | — | %2,3 | 1 Nis 2022 |
40Planlayın | CVE-2020-9297İstismar yok | Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators.netflix · titus · CWE-917 | Kritik9,8 | — | %1,9 | 14 Tem 2020 |
40Planlayın | CVE-2020-9296İstismar yok | Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators.netflix · conductor · CWE-917 | Kritik9,8 | — | %1,7 | 16 Haz 2020 |
37İzleyin | CVE-2024-5023İstismar yok | Arbitrary File Read Vulnerability in ConsoleMe via Limited Git command RCEnetflix · consoleme · CWE-77 | Kritik9,3 | — | %0,9 | 16 May 2024 |
37İzleyin | CVE-2024-7093İstismar yok | Server-Side Template Injection in Dispatch Message Templatesnetflix · dispatch · CWE-94 | Kritik9,4 | — | %0,5 | 1 Ağu 2024 |
34İzleyin | CVE-2024-9301İstismar yok | A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250anetflix · e2nest · CWE-22 | Yüksek8,7 | — | %0,7 | 27 Eyl 2024 |
30İzleyin | CVE-2015-7764İstismar yok | Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.netflix · lemur · CWE-331 | Yüksek7,5 | — | %1,5 | 9 Ağu 2017 |
30İzleyin | CVE-2020-2322İstismar yok | Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Renetflix · chaos monkey · CWE-862 | Yüksek7,5 | — | %1,3 | 3 Ara 2020 |
30İzleyin | CVE-2019-10028İstismar yok | Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.netflix · dial reference | Yüksek7,5 | — | %1,1 | 21 Haz 2019 |
30İzleyin | CVE-2023-40171İstismar yok | Dispatch writes JWT tokens in error messagenetflix · dispatch · CWE-209 | Yüksek7,5 | — | %0,9 | 17 Ağu 2023 |
30İzleyin | CVE-2023-30797İstismar yok | Insecure Random Generation in Netflix Lemurnetflix · lemur · CWE-330 | Yüksek7,5 | — | %0,8 | 19 Nis 2023 |
26İzleyin | CVE-2020-9300İstismar yok | The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselnetflix · dispatch | Orta6,5 | — | %0,9 | 9 Kas 2020 |
24İzleyin | CVE-2017-7266İstismar yok | Netflix Security Monkey before 0.8.0 has an Open Redirect.netflix · security monkey · CWE-601 | Orta6,1 | — | %1,0 | 26 Mar 2017 |
22İzleyin | CVE-2021-28100İstismar yok | Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--.netflix · priam | Orta5,5 | — | %0,3 | 23 Mar 2021 |
21İzleyin | CVE-2020-2323İstismar yok | Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read pernetflix · chaos monkey · CWE-862 | Orta5,3 | — | %0,8 | 3 Ara 2020 |
21İzleyin | CVE-2020-9299İstismar yok | There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Prnetflix · dispatch · CWE-79 | Orta5,4 | — | %0,6 | 9 Kas 2020 |
17İzleyin | CVE-2021-28099İstismar yok | In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories wnetflix · hollow · CWE-330 | Orta4,4 | — | %0,2 | 23 Mar 2021 |
- CVE-2024-470146Planlayın
Path Traversal vulnerability via File Uploads in Genie
KritikCVSS 9,9Kavram kanıtıEPSS %25netflix · genie14 May 2024
- CVE-2022-2717740Planlayın
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to
KritikCVSS 9,8İstismar yokEPSS %2netflix · consoleme1 Nis 2022
- CVE-2020-929740Planlayın
Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators.
KritikCVSS 9,8İstismar yokEPSS %2netflix · titus14 Tem 2020
- CVE-2020-929640Planlayın
Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators.
KritikCVSS 9,8İstismar yokEPSS %2netflix · conductor16 Haz 2020
- CVE-2024-502337İzleyin
Arbitrary File Read Vulnerability in ConsoleMe via Limited Git command RCE
KritikCVSS 9,3İstismar yokEPSS %1netflix · consoleme16 May 2024
- CVE-2024-709337İzleyin
Server-Side Template Injection in Dispatch Message Templates
KritikCVSS 9,4İstismar yokEPSS %1netflix · dispatch1 Ağu 2024
- CVE-2024-930134İzleyin
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
YüksekCVSS 8,7İstismar yokEPSS %1netflix · e2nest27 Eyl 2024
- CVE-2015-776430İzleyin
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
YüksekCVSS 7,5İstismar yokEPSS %2netflix · lemur9 Ağu 2017
- CVE-2020-232230İzleyin
Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Re
YüksekCVSS 7,5İstismar yokEPSS %1netflix · chaos monkey3 Ara 2020
- CVE-2019-1002830İzleyin
Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.
YüksekCVSS 7,5İstismar yokEPSS %1netflix · dial reference21 Haz 2019
- CVE-2023-4017130İzleyin
Dispatch writes JWT tokens in error message
YüksekCVSS 7,5İstismar yokEPSS %1netflix · dispatch17 Ağu 2023
- CVE-2023-3079730İzleyin
Insecure Random Generation in Netflix Lemur
YüksekCVSS 7,5İstismar yokEPSS %1netflix · lemur19 Nis 2023
- CVE-2020-930026İzleyin
The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themsel
OrtaCVSS 6,5İstismar yokEPSS %1netflix · dispatch9 Kas 2020
- CVE-2017-726624İzleyin
Netflix Security Monkey before 0.8.0 has an Open Redirect.
OrtaCVSS 6,1İstismar yokEPSS %1netflix · security monkey26 Mar 2017
- CVE-2021-2810022İzleyin
Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--.
OrtaCVSS 5,5İstismar yokEPSS %0netflix · priam23 Mar 2021
- CVE-2020-232321İzleyin
Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read per
OrtaCVSS 5,3İstismar yokEPSS %1netflix · chaos monkey3 Ara 2020
- CVE-2020-929921İzleyin
There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Pr
OrtaCVSS 5,4İstismar yokEPSS %1netflix · dispatch9 Kas 2020
- CVE-2021-2809917İzleyin
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories w
OrtaCVSS 4,4İstismar yokEPSS %0netflix · hollow23 Mar 2021