Vulnerabilidades en awslabs
10 resultadosAnálisis Vexday
O fornecedor awslabs registra 10 vulnerabilidades na base do Vexday, todas com severidade abaixo do crítico e nenhuma sob exploração ativa conhecida (KEV). A fraqueza dominante é CWE-22 (path traversal), padrão em bibliotecas de infraestrutura, sem incidentes de risco recentes nos últimos 90 dias.
CVE-2021-43811HIGHCode injection via unsafe YAML loadingEPSS 2.4%CVE-2020-15093HIGHImproper verification of signature threshold in toughEPSS 1.4%CVE-2021-41150HIGHImproper sanitization of delegated role names in toughEPSS 1.3%CVE-2023-36467HIGHAWS data.all vulnerable to RCE through user injection of Python CommandsEPSS 1.2%CVE-2021-41149HIGHImproper sanitization of target names in toughEPSS 1.1%CVE-2022-39230MEDIUMSecurity issue in fhir-works-on-aws-authz-smartEPSS 0.7%CVE-2023-50928HIGH sandbox-accounts-for-events security misconfiguration leads to budget exceedEPSS 0.4%CVE-2024-37293HIGHaws-deployment-framework's potential risk can lead to privilege escalationEPSS 0.2%CVE-2023-30610MEDIUMAWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sendingEPSS 0.2%CVE-2023-51386HIGHSandbox Accounts for Events vulnerable to privilege escalation to read running events dataEPSS 0.2%