Vulnerabilidades em ETHER
10 resultadosAnálise Vexday
A ETHER apresenta um perfil de risco moderado com 3 vulnerabilidades catalogadas, sendo 1 crítica e 1 publicada recentemente. Nenhuma das vulnerabilidades está sob ataque ativo no momento, reduzindo a ameaça imediata. A fraqueza dominante é CWE-122 (buffer overflow), que historicamente representa risco elevado em contextos de execução remota de código.
CVE-2021-43802CRITICALAdmin privilege escalation and arbitrary code execution via malicious *.etherpad importsEPSS 2.0%CVE-2025-40907MEDIUMFCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) libraryEPSS 0.6%CVE-2026-55087MEDIUMEtherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)EPSS 0.6%CVE-2026-55090MEDIUMEtherpad: Stored XSS in HTML export via unescaped attribute-pool valuesEPSS 0.5%CVE-2026-55085CRITICALEtherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-liteEPSS 0.5%CVE-2026-55089CRITICALEtherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpointEPSS 0.5%CVE-2026-55088MEDIUMEtherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokenEPSS 0.4%CVE-2025-40920HIGHCatalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl use insecurely generated noncesEPSS 0.4%CVE-2009-10007CRITICALCatalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacksEPSS 0.4%CVE-2026-55086MEDIUMEtherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwriteEPSS 0.1%