Siren
Siren Investigate: vulnerabilidades y CVE
Siren Investigate tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-35857 | Crítica (9.8) | 0.64% | — | 19 jun 2023 | In Siren Investigate before 13.2.2, session keys remain active even after logging out. |
| CVE-2022-47544 | Crítica (9.8) | 0.69% | — | 5 ene 2023 | An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed. |
| CVE-2022-47543 | Media (5.3) | 0.42% | — | 5 ene 2023 | An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects. |
| CVE-2021-36794 | Crítica (9.8) | 1.4% | — | 2 nov 2021 | In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications are disabled globally in the Siren Investigate main process. |
| CVE-2021-31216 | Alta (8.1) | 0.72% | — | 19 jul 2021 | Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate installation can specify… |