Cybelesoft
Cybelesoft Thinfinity Workspace: vulnerabilidades y CVE
Cybelesoft Thinfinity Workspace tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-40410 | Media (4.8) | 0.14% | — | 13 nov 2024 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption. |
| CVE-2024-40408 | Alta (7.3) | 0.28% | — | 13 nov 2024 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated… |
| CVE-2024-40407 | Alta (7.5) | 0.39% | — | 13 nov 2024 | A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors. |
| CVE-2024-40405 | Alta (8.1) | 0.45% | — | 13 nov 2024 | Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request. |
| CVE-2024-40404 | Crítica (9.8) | 0.46% | — | 13 nov 2024 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established. |