projectcontour kayıtları
projectcontour üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %20
- Silahlaştırılmış
- 1 · %20
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %80
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-277 Insecure Inherited Permissions1
- CWE-306 Missing Authentication for Critical Function1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
39İzleyin | CVE-2024-36539Kavram kanıtı | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account'sprojectcontour · contour · CWE-277 | Kritik9,8 | — | %1,3 | 24 Tem 2024 |
34İzleyin | CVE-2021-32783İstismar yok | Authorization bypass in Contourprojectcontour · contour · CWE-441 | Yüksek8,5 | — | %1,2 | 23 Tem 2021 |
32İzleyin | CVE-2026-41246İstismar yok | Contour: Lua code injection via Cookie Path Rewrite Policyprojectcontour · contour · CWE-94 | Yüksek8,1 | — | %0,8 | 23 Nis 2026 |
30İzleyin | CVE-2020-15127İstismar yok | Denial of service in Contourprojectcontour · contour · CWE-306 | Yüksek7,5 | — | %1,4 | 5 Ağu 2020 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2024-3653939İzleyin
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's
KritikCVSS 9,8Kavram kanıtıEPSS %1projectcontour · contour24 Tem 2024
- CVE-2021-3278334İzleyin
Authorization bypass in Contour
YüksekCVSS 8,5İstismar yokEPSS %1projectcontour · contour23 Tem 2021
- CVE-2026-4124632İzleyin
Contour: Lua code injection via Cookie Path Rewrite Policy
YüksekCVSS 8,1İstismar yokEPSS %1projectcontour · contour23 Nis 2026
- CVE-2020-1512730İzleyin
Denial of service in Contour
YüksekCVSS 7,5İstismar yokEPSS %1projectcontour · contour5 Ağu 2020