OliveTin kayıtları
olivetin üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-284 Improper Access Control2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-250 Execution with Unnecessary Privileges1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-384 Session Fixation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-27626Kavram kanıtı | OliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checksolivetin · olivetin · CWE-78 | Kritik9,9 | — | %0,7 | 24 Şub 2026 |
35İzleyin | CVE-2026-30223İstismar yok | OliveTin: JWT Audience Validation Bypass in Local Key and HMAC Modesolivetin · olivetin · CWE-287 | Yüksek8,8 | — | %0,3 | 6 Mar 2026 |
34İzleyin | CVE-2026-31817İstismar yok | OliveTin's unsafe parsing of UniqueTrackingId can be used to write filesolivetin · olivetin · CWE-22 | Yüksek8,5 | — | %0,9 | 10 Mar 2026 |
30İzleyin | CVE-2026-28342İstismar yok | OliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpointolivetin · olivetin · CWE-400 | Yüksek7,5 | — | %0,8 | 5 Mar 2026 |
30İzleyin | CVE-2026-28790İstismar yok | OliveTin: Unauthenticated Action Termination via KillAction When Guests Must Loginolivetin · olivetin · CWE-284 | Yüksek7,5 | — | %0,8 | 5 Mar 2026 |
30İzleyin | CVE-2026-28789İstismar yok | OliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handlingolivetin · olivetin · CWE-362 | Yüksek7,5 | — | %0,5 | 5 Mar 2026 |
28İzleyin | CVE-2026-32102İstismar yok | OliveTin Unauthorized Action Output Disclosure via EventStreamolivetin · olivetin · CWE-284 | Yüksek7,1 | — | %0,5 | 11 Mar 2026 |
26İzleyin | CVE-2025-50946Kavram kanıtı | OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.olivetin · olivetin · CWE-78 | Orta6,5 | — | %1,3 | 13 Ağu 2025 |
21İzleyin | CVE-2026-30224İstismar yok | OliveTin: Session Fixation - Logout Fails to Invalidate Server-Side Sessionolivetin · olivetin · CWE-384 | Orta5,4 | — | %0,4 | 6 Mar 2026 |
17İzleyin | CVE-2026-30225Kavram kanıtı | OliveTin: RestartAction always runs actions as guestolivetin · olivetin · CWE-250 | Orta4,3 | — | %0,6 | 6 Mar 2026 |
17İzleyin | CVE-2026-30233İstismar yok | OliveTin: View permission not being checked when returning dashboardsolivetin · olivetin · CWE-200 | Orta4,3 | — | %0,5 | 6 Mar 2026 |
- CVE-2026-2762639İzleyin
OliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checks
KritikCVSS 9,9Kavram kanıtıEPSS %1olivetin · olivetin24 Şub 2026
- CVE-2026-3022335İzleyin
OliveTin: JWT Audience Validation Bypass in Local Key and HMAC Modes
YüksekCVSS 8,8İstismar yokEPSS %0olivetin · olivetin6 Mar 2026
- CVE-2026-3181734İzleyin
OliveTin's unsafe parsing of UniqueTrackingId can be used to write files
YüksekCVSS 8,5İstismar yokEPSS %1olivetin · olivetin10 Mar 2026
- CVE-2026-2834230İzleyin
OliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint
YüksekCVSS 7,5İstismar yokEPSS %1olivetin · olivetin5 Mar 2026
- CVE-2026-2879030İzleyin
OliveTin: Unauthenticated Action Termination via KillAction When Guests Must Login
YüksekCVSS 7,5İstismar yokEPSS %1olivetin · olivetin5 Mar 2026
- CVE-2026-2878930İzleyin
OliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handling
YüksekCVSS 7,5İstismar yokEPSS %0olivetin · olivetin5 Mar 2026
- CVE-2026-3210228İzleyin
OliveTin Unauthorized Action Output Disclosure via EventStream
YüksekCVSS 7,1İstismar yokEPSS %0olivetin · olivetin11 Mar 2026
- CVE-2025-5094626İzleyin
OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.
OrtaCVSS 6,5Kavram kanıtıEPSS %1olivetin · olivetin13 Ağu 2025
- CVE-2026-3022421İzleyin
OliveTin: Session Fixation - Logout Fails to Invalidate Server-Side Session
OrtaCVSS 5,4İstismar yokEPSS %0olivetin · olivetin6 Mar 2026
- CVE-2026-3022517İzleyin
OliveTin: RestartAction always runs actions as guest
OrtaCVSS 4,3Kavram kanıtıEPSS %1olivetin · olivetin6 Mar 2026
- CVE-2026-3023317İzleyin
OliveTin: View permission not being checked when returning dashboards
OrtaCVSS 4,3İstismar yokEPSS %0olivetin · olivetin6 Mar 2026