Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

E2nest HIGH 7.5
CVE-2024-9301

A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a

Fix: 2024-09-05+
Fix from $1,950 2024-09-27
Dispatch HIGH 7.5
CVE-2023-40171

Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error me…

Fix: 20230817+
Fix from $1,950 2023-08-17
Lemur HIGH 7.5
CVE-2023-30797

Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow …

Fix: 1.3.2+
Fix from $1,950 2023-04-19
Consoleme CRITICAL 9.8
CVE-2022-27177

A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2

Fix: 1.2.2+
Fix from $2,300 2022-04-01
Priam MEDIUM 5.5
CVE-2021-28100

Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read an…

Mitigation only
Fix from $1,600 2021-03-23
Chaos Monkey HIGH 7.5
CVE-2020-2322

Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permis…

Fix: after 0.3
Fix from $1,950 2020-12-03
Chaos Monkey MEDIUM 5.3
CVE-2020-2323

Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission t…

Fix: after 0.4
Fix from $1,600 2020-12-03
Dispatch MEDIUM 6.5
CVE-2020-9300

The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a …

Fix: 20201106+
Fix from $1,600 2020-11-09
Dispatch MEDIUM 5.4
CVE-2020-9299

There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, I…

Fix: 20201106+
Fix from $1,600 2020-11-09
Titus CRITICAL 9.8
CVE-2020-9297

Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom co…

Fix: after 0.1.0
Fix from $2,300 2020-07-14
Conductor CRITICAL 9.8
CVE-2020-9296

Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different t…

Fix: after 2.25.3
Fix from $2,300 2020-06-16
Dial Reference HIGH 7.5
CVE-2019-10028

Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.

Fix: 6-18-2019+
Fix from $1,950 2019-06-21
Lemur HIGH 7.5
CVE-2015-7764

Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.

Mitigation only
Fix from $1,950 2017-08-09
Security Monkey MEDIUM 6.1
CVE-2017-7266

Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain …

Fix: after 0.7.0
Fix from $1,600 2017-03-26