Vulnerabilidades en Netflix

23 resultados
Análisis Vexday

A Netflix apresenta um portfólio moderado de 9 vulnerabilidades na base, com 4 classificadas como críticas, mas nenhuma sob ataque ativo confirmado no momento. A fraqueza dominante é CWE-22 (path traversal), e o ritmo recente de 2 divulgações nos últimos 90 dias indica atividade contínua, exigindo monitoramento das correções críticas disponibilizadas.

CVE-2024-4701CRITICALPath Traversal vulnerability via File Uploads in GenieEPSS 24.6%CVE-2019-10028—Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.EPSS 1.1%CVE-2024-5023CRITICALArbitrary File Read Vulnerability in ConsoleMe via Limited Git command RCEEPSS 0.9%CVE-2023-40171CRITICALDispatch writes JWT tokens in error messageEPSS 0.9%CVE-2023-30797HIGHInsecure Random Generation in Netflix LemurEPSS 0.8%CVE-2024-9301HIGHA path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250aEPSS 0.7%CVE-2024-7093CRITICALServer-Side Template Injection in Dispatch Message TemplatesEPSS 0.5%CVE-2026-48508HIGHLemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermissionEPSS 0.3%CVE-2026-71308HIGHLemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificatesEPSS 0.3%CVE-2026-71307HIGHLemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations APIEPSS 0.3%CVE-2026-55164MEDIUMLemur: Plaintext password storage in Lemur user-update pathEPSS 0.3%CVE-2026-44304HIGHLemur: LDAP Filter Injection enables post-authentication privilege escalationEPSS 0.3%CVE-2026-55166CRITICALLemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOREPSS 0.3%CVE-2026-71303HIGHLemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlistEPSS 0.3%CVE-2026-71322MEDIUMLemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = FalseEPSS 0.2%CVE-2026-55162MEDIUMLemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and OCSP URLs in uploaded certificatesEPSS 0.2%CVE-2026-70666HIGHLemur: Server-Side Request Forgery via the ACME client following server-controlled URLsEPSS 0.2%CVE-2026-55163MEDIUMLemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite role membershipEPSS 0.2%CVE-2026-70667MEDIUMLemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for CVE-2026-55162)EPSS 0.2%CVE-2026-55165MEDIUMLemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosureEPSS 0.2%