Netflix
Netflix Lemur: vulnerabilidades y CVE
Netflix Lemur tiene 18 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses16
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71417 | Alta (7.3) | 0.10% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or external_id without… |
| CVE-2026-71322 | Media (4.3) | 0.23% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/certificates//export. A plugin declaring… |
| CVE-2026-71317 | Media (6.5) | 0.10% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORITY_CREATION was false.… |
| CVE-2026-71308 | Alta (8.1) | 0.32% | — | 18 ago 2026 | Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects… |
| CVE-2026-71307 | Alta (7.7) | 0.31% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema… |
| CVE-2026-71303 | Alta (7.7) | 0.28% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but PUT /api/1/authorities/ passed options to lemur/authorities/service.py… |
| CVE-2026-70666 | Alta (7.4) | 0.22% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalidation and direct setup_acme_client_no_retry to an attacker-controlled… |
| CVE-2026-70667 | Media (6.3) | 0.18% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a different destination. The CRL… |
| CVE-2026-55166 | Crítica (9.9) | 0.29% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client… |
| CVE-2026-55165 | Media (4.8) | 0.15% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_header to read header_data["alg"] from an unverified token and passed that attacker-controlled… |
| CVE-2026-55164 | Media (4.9) | 0.29% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the… |
| CVE-2026-55163 | Media (6.3) | 0.22% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(role_id), which allowed either an administrator or any existing member… |
| CVE-2026-55162 | Media (6.3) | 0.22% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from uploaded certificate extensions and used them in crl_verify and… |
| CVE-2026-48508 | Alta (8.8) | 0.33% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when… |
| CVE-2026-44305 | Media (6.8) | 0.14% | — | 12 may 2026 | Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module… |
| CVE-2026-44304 | Alta (8.1) | 0.29% | — | 12 may 2026 | Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An… |
| CVE-2023-30797 | Alta (7.5) | 0.79% | — | 19 abr 2023 | Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources… |
| CVE-2015-7764 | Alta (7.5) | 1.5% | — | 9 ago 2017 | Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.