Sandstorm
Sandstorm: vulnerabilities and CVEs
Sandstorm has 4 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6201 | High (8.1) | 1.9% | — | Feb 6, 2018 | A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could bypass access control such as… |
| CVE-2017-6200 | Medium (6.5) | 2.3% | — | Feb 6, 2018 | Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter Line Feed (\n)… |
| CVE-2017-6199 | Critical (9.8) | 3.0% | — | Feb 6, 2018 | A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field. |
| CVE-2017-6198 | Medium (6.5) | 1.4% | — | Feb 6, 2018 | The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by launching a fork bomb in the sandbox, or by using a large amount of disk… |