« Back to list

Clinical-genomics

Clinical-genomics Scout: vulnerabilities and CVEs

Clinical-genomics Scout has 4 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-47531Low (3.5)0.33%—Sep 30, 2024
Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious…
CVE-2024-47530Medium (6.1)0.39%—Sep 30, 2024
Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicious page. /login API endpoint is vulnerable to open redirect attack via…
CVE-2022-1592High (8.2)1.2%—May 5, 2022
Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or…
CVE-2022-1554High (7.5)1.4%—May 3, 2022
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.