Filtered by vendor Stackstorm
Subscribe
Search
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-20345 | 1 Stackstorm | 1 Stackstorm | 2020-08-24 | 3.5 LOW | 5.3 MEDIUM |
| Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackStorm account and is authenticated against the StackStorm API) to retrieve datastore items for other users by utilizing the /v1/keys "?scope=all" and "?user=<username>" query filter parameters. Enterprise editions with RBAC enabled are not affected. | |||||
| CVE-2019-9580 | 1 Stackstorm | 1 Stackstorm | 2019-03-12 | 4.3 MEDIUM | 6.1 MEDIUM |
| In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS. | |||||
