sourcegraph kayıtları
sourcegraph üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %9,1
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %63,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-863 Incorrect Authorization2
- CWE-276 Incorrect Default Permissions1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-15 External Control of System or Configuration Setting1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2022-23642Silahlaştırılmış | Code Injection in Sourcegraphsourcegraph · sourcegraph · CWE-94 | Yüksek8,8 | — | %74,3 | 18 Şub 2022 |
35İzleyin | CVE-2023-46248İstismar yok | Overwrite of builtin Cody commands facilitates RCEsourcegraph · cody · CWE-15 | Yüksek8,8 | — | %1,1 | 31 Eki 2023 |
32İzleyin | CVE-2022-41942İstismar yok | Sourcegraph vulnerable to Comand Injection via gitserversourcegraph · sourcegraph · CWE-20 | Yüksek7,8 | — | %2,8 | 22 Kas 2022 |
29İzleyin | CVE-2022-41943İstismar yok | Incorrect default permissions found in Sourcegraphsourcegraph · sourcegraph · CWE-276 | Yüksek7,2 | — | %1,8 | 22 Kas 2022 |
28İzleyin | CVE-2022-29171İstismar yok | Remote Code Execution in sourcegraphsourcegraph · sourcegraph · CWE-74 | Yüksek7,2 | — | %1,4 | 5 May 2022 |
26İzleyin | CVE-2021-43823İstismar yok | Side-channel attack in Sourcegraphsourcegraph · sourcegraph · CWE-200 | Orta6,5 | — | %0,8 | 13 Ara 2021 |
26İzleyin | CVE-2022-23643İstismar yok | Side-channel attack in Sourcegraph Code Monitorssourcegraph · sourcegraph · CWE-200 | Orta6,5 | — | %0,8 | 15 Şub 2022 |
24İzleyin | CVE-2020-12283İstismar yok | Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontsourcegraph · sourcegraph · CWE-601 | Orta6,1 | — | %1,3 | 30 Nis 2020 |
17İzleyin | CVE-2021-32787İstismar yok | Low risk information disclosure in Sourcegraphsourcegraph · sourcegraph · CWE-200 | Orta4,3 | — | %0,6 | 2 Ağu 2021 |
17İzleyin | CVE-2022-31154İstismar yok | Indirect Object Access in Sourcegraph Code Monitoringsourcegraph · sourcegraph · CWE-863 | Orta4,3 | — | %0,5 | 1 Ağu 2022 |
17İzleyin | CVE-2022-31155İstismar yok | Unauthorized overwriting of saved searches in Sourcegraphsourcegraph · sourcegraph · CWE-863 | Orta4,3 | — | %0,5 | 1 Ağu 2022 |
- CVE-2022-2364257Planlayın
Code Injection in Sourcegraph
YüksekCVSS 8,8SilahlaştırılmışEPSS %74sourcegraph · sourcegraph18 Şub 2022
- CVE-2023-4624835İzleyin
Overwrite of builtin Cody commands facilitates RCE
YüksekCVSS 8,8İstismar yokEPSS %1sourcegraph · cody31 Eki 2023
- CVE-2022-4194232İzleyin
Sourcegraph vulnerable to Comand Injection via gitserver
YüksekCVSS 7,8İstismar yokEPSS %3sourcegraph · sourcegraph22 Kas 2022
- CVE-2022-4194329İzleyin
Incorrect default permissions found in Sourcegraph
YüksekCVSS 7,2İstismar yokEPSS %2sourcegraph · sourcegraph22 Kas 2022
- CVE-2022-2917128İzleyin
Remote Code Execution in sourcegraph
YüksekCVSS 7,2İstismar yokEPSS %1sourcegraph · sourcegraph5 May 2022
- CVE-2021-4382326İzleyin
Side-channel attack in Sourcegraph
OrtaCVSS 6,5İstismar yokEPSS %1sourcegraph · sourcegraph13 Ara 2021
- CVE-2022-2364326İzleyin
Side-channel attack in Sourcegraph Code Monitors
OrtaCVSS 6,5İstismar yokEPSS %1sourcegraph · sourcegraph15 Şub 2022
- CVE-2020-1228324İzleyin
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/front
OrtaCVSS 6,1İstismar yokEPSS %1sourcegraph · sourcegraph30 Nis 2020
- CVE-2021-3278717İzleyin
Low risk information disclosure in Sourcegraph
OrtaCVSS 4,3İstismar yokEPSS %1sourcegraph · sourcegraph2 Ağu 2021
- CVE-2022-3115417İzleyin
Indirect Object Access in Sourcegraph Code Monitoring
OrtaCVSS 4,3İstismar yokEPSS %0sourcegraph · sourcegraph1 Ağu 2022
- CVE-2022-3115517İzleyin
Unauthorized overwriting of saved searches in Sourcegraph
OrtaCVSS 4,3İstismar yokEPSS %0sourcegraph · sourcegraph1 Ağu 2022