Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown

CVE-2023-30962

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
Attacker Value
Unknown

CVE-2023-30952

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 .
Attacker Value
Unknown

CVE-2023-30951

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).
Attacker Value
Unknown

CVE-2023-30950

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
Attacker Value
Unknown

CVE-2023-30949

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.
Attacker Value
Unknown

CVE-2023-30963

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.229.0. The service was rolled out to all affected Foundry instances. No further intervention is required.
Attacker Value
Unknown

CVE-2023-30960

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required.
Attacker Value
Unknown

CVE-2023-30956

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.
Attacker Value
Unknown

CVE-2023-22835

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue that caused loss of frontend functionality to all issue participants. This defect was resolved with the release of Foundry Issues 2.510.0 and Foundry Frontend 6.228.0.
Attacker Value
Unknown

CVE-2023-30955

Disclosure Date: June 29, 2023 (last updated October 08, 2023)
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with workspace-server 7.7.0.