Vulnerabilities (CVE)

Filtered by vendor Mitre Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42558 1 Mitre 1 Caldera 2022-01-19 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.
CVE-2020-10807 1 Mitre 1 Caldera 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
CVE-2020-14462 1 Mitre 1 Caldera 2020-06-19 3.5 LOW 5.4 MEDIUM
CALDERA 2.7.0 allows XSS via the Operation Name box.