Vulnerabilidades en craigjbass
8 resultadosAnálisis Vexday
O fornecedor craigjbass apresenta 8 vulnerabilidades catalogadas, com 2 divulgadas nos últimos 90 dias, mas nenhuma sob exploração ativa conhecida ou com severidade crítica. A fraqueza dominante (CWE-862 - falta de autorização) sugere problemas de controle de acesso, exigindo revisão de permissões e validação de autenticação nos componentes afetados.
CVE-2026-34218MEDIUMClearanceKit: Managed and user-defined policy rules not enforced between opfilter start and first policy modificationEPSS 0.2%CVE-2026-47133MEDIUMClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshotsEPSS 0.2%CVE-2026-47134MEDIUMClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policyEPSS 0.2%CVE-2026-40599HIGHClearanceKit: Ad-hoc signed binaries can spoof Apple process identities in the global allowlistEPSS 0.1%CVE-2026-40191MEDIUMClearanceKit has a policy bypass via dual-path Endpoint Security events checking only source pathEPSS 0.1%CVE-2026-40604HIGHClearanceKit: opfilter system extension can be suspended or signalled by a root process, disabling file-access policy enforcementEPSS 0.1%CVE-2026-33631HIGHClearanceKit: opfilter policy bypass via non-open file operationsEPSS 0.1%CVE-2026-33632HIGHClearanceKit: opfilter policy bypass via exchangedata and clone operationsEPSS 0.1%