Vulnerabilidades em ether
10 resultadosAnálise Vexday
O fornecedor Ether apresenta uma vulnerabilidade crítica catalogada, sem evidências de exploração ativa no momento. A fraqueza identificada (CWE-1287, relacionada a validação de configuração) é isolada e não recente, representando um risco contido que merece acompanhamento rotineiro mas não demanda ação imediata.
CVE-2021-43802CRITICALAdmin privilege escalation and arbitrary code execution via malicious *.etherpad importsEPSS 2.0%CVE-2025-40907MEDIUMFCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) libraryEPSS 0.6%CVE-2026-55087MEDIUMEtherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)EPSS 0.6%CVE-2026-55090MEDIUMEtherpad: Stored XSS in HTML export via unescaped attribute-pool valuesEPSS 0.5%CVE-2026-55085CRITICALEtherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-liteEPSS 0.5%CVE-2026-55089CRITICALEtherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpointEPSS 0.5%CVE-2026-55088MEDIUMEtherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokenEPSS 0.4%CVE-2025-40920HIGHCatalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl use insecurely generated noncesEPSS 0.4%CVE-2009-10007CRITICALCatalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacksEPSS 0.4%CVE-2026-55086MEDIUMEtherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwriteEPSS 0.1%