Aggregates CVE and security vulnerability intelligence across all immuta-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk cross-site scripting, with potential vendor impact session compromise across vendor surface software deployment and vendor surface production workloads use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2020-15952 | Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS. | [email protected] | 9.0 | 1.53% | 2020-11-05 | 2026-06-16 |
| CVE-2020-15951 | Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials. | [email protected] | 6.1 | 0.96% | 2020-11-05 | 2026-06-16 |
| CVE-2020-15950 | Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout. | [email protected] | 8.8 | 1.30% | 2020-11-05 | 2026-06-16 |
| CVE-2020-15949 | Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover. | [email protected] | 7.5 | 1.27% | 2020-11-05 | 2026-06-16 |