« Back to list

Conda-forge

Conda-forge-webservices: vulnerabilities and CVEs

Conda-forge-webservices has 2 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-49842Low (1)0.18%—Jun 17, 2025
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.24, the conda_forge_webservice Docker container executes commands without specifying a user. By…
CVE-2025-32784High (7.5)0.26%—Apr 15, 2025
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025.4.10, a race condition vulnerability has been identified in the conda-forge-webservices component…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services1
  2. T1565.002 Transmitted Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Conda-forge