Ethyca
Ethyca Fides: vulnerabilidades y CVE
Ethyca Fides tiene 22 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-44541 | Alta (7) | 0.52% | — | 8 jun 2026 | Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in… |
| CVE-2026-42303 | Media (6.1) | 0.55% | — | 12 may 2026 | Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a… |
| CVE-2025-57817 | Alta (8.6) | 0.42% | — | 8 sept 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize scope assignment. This allows highly… |
| CVE-2025-57816 | Media (6.3) | 0.43% | — | 8 sept 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system… |
| CVE-2025-57815 | Baja (1.7) | 0.29% | — | 8 sept 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lacks specific anti-automation controls… |
| CVE-2025-57766 | Baja (1.7) | 0.30% | — | 8 sept 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vulnerability chaining opportunity where… |
| CVE-2024-52008 | Baja (2) | 0.56% | — | 26 nov 2024 | Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side… |
| CVE-2024-45053 | Alta (7.2) | 1.3% | — | 4 sept 2024 | Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitization or rendering environment… |
| CVE-2024-45052 | Media (5.3) | 0.56% | — | 4 sept 2024 | Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an unauthenticated… |
| CVE-2024-31223 | Media (5.3) | 1.1% | — | 3 jul 2024 | Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to communicate with the Fides webserver backend.… |
| CVE-2024-38537 | Crítica (9.8) | 1.4% | — | 2 jul 2024 | Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domain in a very limited edge case, when it… |
| CVE-2024-35189 | Media (6.5) | 0.58% | — | 30 may 2024 | Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ contain sensitive data (e.g.… |
| CVE-2024-34715 | Baja (3.3) | 0.27% | — | 29 may 2024 | Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL database for persistent storage of application data. If the password used by the webserver for this… |
| CVE-2023-48224 | Crítica (9.1) | 0.99% | — | 15 nov 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides Privacy Center allows… |
| CVE-2023-47114 | Media (6.1) | 0.61% | — | 8 nov 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in your runtime environment, and the enforcement of privacy regulations in your code. The Fides web application… |
| CVE-2023-46126 | Media (5.4) | 0.61% | — | 25 oct 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, helping enforce privacy regulations in code. The Fides web application allows users to… |
| CVE-2023-46125 | Media (6.5) | 0.73% | — | 25 oct 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows… |
| CVE-2023-46124 | Alta (7.2) | 0.68% | — | 25 oct 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in code. The Fides web application allows a… |
| CVE-2023-41319 | Alta (7.2) | 0.94% | — | 6 sept 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows… |
| CVE-2023-37481 | Media (4.9) | 0.70% | — | 18 jul 2023 | Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fides webserver is vulnerable to a type of Denial of Service (DoS) attack. Attackers can exploit this… |
| CVE-2023-37480 | Media (4.9) | 0.69% | — | 18 jul 2023 | Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fides webserver is vulnerable to a type of Denial of Service (DoS) attack. Attackers can exploit a… |
| CVE-2023-36827 | Alta (7.5) | 1.5% | — | 5 jul 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. A path traversal (directory… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.