Vulnerabilidades em Enalean

62 resultados
Análise Vexday

Com 62 CVEs catalogadas e nenhuma em exploração ativa no catálogo KEV da CISA, o perfil de risco do vendor Enalean situa-se abaixo da média geral do catálogo em termos de exploração confirmada. A ausência de falhas críticas, provas de conceito públicas e registros recentes nos últimos 90 dias indica estabilidade momentânea na superfície de ataque, embora o histórico acumulado mereça monitoramento contínuo. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, quando não mitigado sistematicamente, pode facilitar ataques de injeção de conteúdo em interfaces web. A CVE mais relevante no momento, CVE-2021-41147, apresenta EPSS de 0,018, sinalizando probabilidade de exploração relativamente baixa, mas suficiente para justificar verificação de aplicação de correções em ambientes que ainda executem versões afetadas.

CVE-2021-41147HIGHSQL injection in the planning edition panelEPSS 1.8%CVE-2021-43806HIGHSQL injection in TuleapEPSS 1.5%CVE-2021-41276MEDIUMIndirect LDAP injection in TuleapEPSS 1.5%CVE-2021-41154HIGHSQL injection in the "SVN core" commits browserEPSS 1.5%CVE-2021-41148HIGHThe update of the CI job targeted by a widget is vulnerable to blind SQL injectionsEPSS 1.5%CVE-2021-41155HIGHSQL injection in CVS revisions browserEPSS 1.5%CVE-2022-31058HIGHSQL injection via the field name of a tracker in TuleapEPSS 1.4%CVE-2021-43782MEDIUMIndirect LDAP injection in TuleapEPSS 1.4%CVE-2022-31032MEDIUMResources of private projects can be exposed in TuleapEPSS 0.9%CVE-2022-24896MEDIUMTracker report renderer and chart widgets leak information in TuleapEPSS 0.7%CVE-2021-41142MEDIUMXSS via the name of a deleted attachmentEPSS 0.7%CVE-2022-31063MEDIUMCross site scripting via the title of a document in TuleapEPSS 0.6%CVE-2022-39233MEDIUMTuleap subject to Missing Authorization allowing for branch prefix modificationEPSS 0.6%CVE-2024-30246HIGHTuleap deleting or moving an artifact can delete values from unrelated artifactsEPSS 0.6%CVE-2022-31128MEDIUMFine grained permissions are not checked in TuleapEPSS 0.6%CVE-2023-35938MEDIUMUser access not updated with privilege change in TuleapEPSS 0.6%CVE-2024-23344MEDIUMTuleap's content of artifacts might be readable by unauthorized usersEPSS 0.5%CVE-2023-38508MEDIUMTuleap allows preview of a linked artifact with a type does not respect permissionsEPSS 0.5%CVE-2023-48715MEDIUMTuleap vulnerable to Cross-site Scripting on the edition page of a releaseEPSS 0.5%CVE-2024-47766MEDIUMPermissions are incorrectly verified for project administrators in the cross tracker search widgetEPSS 0.5%