fiware keyrock の CVE(5 件)

CVE 件数: 5 CPE versions: View versions table

概要

本ページは fiware keyrock に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 15 / 5 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2024-42167 The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands by creating an application with a malicious organisationname. [email protected] 9.1 0.18% 2024-08-12 2024-08-29
CVE-2024-42166 The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands by creating an application with a malicious name. [email protected] 9.1 0.18% 2024-08-12 2024-08-29
CVE-2024-42165 Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accounts of any user by predicting the token for the activation link. [email protected] 6.3 0.09% 2024-08-12 2024-08-29
CVE-2024-42164 Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link. [email protected] 4.3 0.11% 2024-08-12 2024-08-29
CVE-2024-42163 Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting the token for the password reset link. [email protected] 8.3 0.05% 2024-08-12 2024-08-29
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence