Lfprojects
Lfprojects Minder: vulnerabilidades y CVE
Lfprojects Minder tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-37904 | Media (5.7) | 0.46% | — | 18 jun 2024 | Minder is an open source Software Supply Chain Security Platform. Minder's Git provider is vulnerable to a denial of service from a maliciously configured GitHub repository. The Git provider clones users repositories… |
| CVE-2024-35238 | Media (5.3) | 0.53% | — | 27 may 2024 | Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerable to a denial-of-service (DoS) attack which could allow an attacker to crash the Minder server and… |
| CVE-2024-35194 | Media (5.3) | 0.41% | — | 20 may 2024 | Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial of service from memory exhaustion that can be triggered from maliciously created templates. Minder… |
| CVE-2024-35185 | Media (5.3) | 0.46% | — | 16 may 2024 | Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack via an attacker-controlled REST endpoint that can crash the Minder… |
| CVE-2024-34084 | Alta (7.5) | 0.59% | — | 7 may 2024 | Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and as such the request is still untrusted at… |
| CVE-2024-31455 | Media (4.3) | 0.77% | — | 9 abr 2024 | Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit `5c381cf` added the ability to get GitHub repositories registered to a project without specifying a specific… |
| CVE-2024-27916 | Media (4.3) | 0.67% | — | 21 mar 2024 | Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRepositoryByName`, `DeleteRepositoryByName`, and `GetArtifactByName` to access any repository in the… |
| CVE-2024-27093 | Alta (7.5) | 0.55% | — | 26 feb 2024 | Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a invalid or differing upstream ID, which causes Minder to report the… |