Lucene search

K

Cloverdx Security Vulnerabilities

cve
cve

CVE-2023-31056

CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and...

9.1CVSS

6.4AI Score

0.001EPSS

2023-04-24 03:15 AM
10
cve
cve

CVE-2021-42776

CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration...

7.7CVSS

7.5AI Score

0.001EPSS

2021-12-01 05:15 PM
10
cve
cve

CVE-2021-30133

A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and...

6.1CVSS

5.9AI Score

0.001EPSS

2021-06-09 03:15 PM
21
cve
cve

CVE-2021-29995

A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX...

8.8CVSS

8.8AI Score

0.015EPSS

2021-06-09 03:15 PM
64
5