İçeriğe atla
Noroxi

stackstorm kayıtları

stackstorm üreticisine ait 6 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%16,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

  1. 18
  2. 19
  3. 21
  4. 22

Çubuk: toplam · koyu kısım: CISA KEV.

Tüm kayıtlar

6 kayıt
  • CVE-2021-44657
    36İzleyin

    In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands

    YüksekCVSS 8,8İstismar yokEPSS %2

    stackstorm · stackstorm15 Ara 2021

  • CVE-2021-28667
    31İzleyin

    StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space.

    YüksekCVSS 7,5İstismar yokEPSS %2

    stackstorm · stackstorm17 Mar 2021

  • CVE-2022-44009
    30İzleyin

    Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to a

    YüksekCVSS 7,5İstismar yokEPSS %1

    stackstorm · stackstorm5 Ara 2022

  • CVE-2019-9580
    25İzleyin

    In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" or

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    stackstorm · stackstorm9 Mar 2019

  • CVE-2018-20345
    21İzleyin

    Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackS

    OrtaCVSS 5,3İstismar yokEPSS %1

    stackstorm · stackstorm21 Ara 2018

  • CVE-2022-43706
    21İzleyin

    Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pa

    OrtaCVSS 5,4İstismar yokEPSS %0

    stackstorm · stackstorm5 Ara 2022