etherpad CVE 脆弱性と CVE 一覧(19)

製品(CPE): — CVE 件数: 19

etherpad 脆弱性概要

etherpad 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

過去の問題は主に パス処理の欠陥 and vendor risk input validation などに関し、一部は vendor impact session compromise を招き、vendor surface software deployment and vendor surface production workloads 関連の場面に影響します。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 119 / 19 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2021-43802 Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin privileges for the Etherpad instance. This, in turn, can be used to install a malicious Etherpad plugin that can execute arbitrary code (including system commands). To gain privileges, the attacker must be able to trigger deletion of `express-session` state or wait for old `express-session` state to be cleaned up. Core E [email protected] 9.9 0.55% 2021-12-09 2024-11-21
CVE-2021-34816 An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source. [email protected] 7.2 0.44% 2021-07-21 2024-11-21
CVE-2021-34817 A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importing a crafted pad. [email protected] 6.1 1.15% 2021-07-19 2024-11-21
CVE-2020-22785 Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check. [email protected] 7.5 0.28% 2021-04-28 2024-11-21
CVE-2020-22784 In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names. [email protected] 7.5 0.24% 2021-04-28 2024-11-21
CVE-2020-22783 Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad. [email protected] 6.5 0.07% 2021-04-28 2024-11-21
CVE-2020-22782 Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance. [email protected] 7.5 0.28% 2021-04-28 2024-11-21
CVE-2020-22781 In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance). [email protected] 7.5 0.37% 2021-04-28 2024-11-21
CVE-2015-3309 Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is due to an incomplete fix to CVE-2015-3297. [email protected] 7.5 0.43% 2020-02-13 2024-11-21
CVE-2019-18209 templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer. [email protected] 6.1 0.33% 2019-10-19 2024-11-21
CVE-2018-9845 Etherpad Lite before 1.6.4 is exploitable for admin access. [email protected] 9.8 77.23% 2018-04-29 2024-11-21
CVE-2018-9327 Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB). [email protected] 8.1 1.04% 2018-04-07 2024-11-21
CVE-2018-9326 Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code. [email protected] 9.8 1.04% 2018-04-07 2024-11-21
CVE-2018-9325 Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names. [email protected] 7.5 0.32% 2018-04-07 2024-11-21
CVE-2018-6835 node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions. [email protected] 9.8 0.36% 2018-02-08 2024-11-21
CVE-2018-6834 static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href. [email protected] 6.1 0.33% 2018-02-08 2024-11-21
CVE-2015-2298 node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID. [email protected] 7.5 0.16% 2018-01-12 2024-11-21
CVE-2015-4085 Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1. [email protected] 7.5 0.39% 2017-09-07 2026-05-13
CVE-2015-3297 Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests. [email protected] 7.5 3.81% 2017-07-07 2026-05-13
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence