Show filters
249 Total Results
Displaying 121-130 of 249
Sort by:
Attacker Value
Unknown
CVE-2020-11987
Disclosure Date: February 24, 2021 (last updated February 22, 2025)
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
0
Attacker Value
Unknown
CVE-2020-13462
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.
0
Attacker Value
Unknown
CVE-2020-13460
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.
0
Attacker Value
Unknown
CVE-2020-13408
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 2 of 3)
0
Attacker Value
Unknown
CVE-2020-13407
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 1 of 3)
0
Attacker Value
Unknown
CVE-2020-13461
Disclosure Date: February 09, 2021 (last updated November 28, 2024)
Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames".
0
Attacker Value
Unknown
CVE-2020-13409
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 3 of 3)
0
Attacker Value
Unknown
CVE-2021-25766
Disclosure Date: February 03, 2021 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.
0
Attacker Value
Unknown
CVE-2021-25771
Disclosure Date: February 03, 2021 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.
0
Attacker Value
Unknown
CVE-2021-25770
Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
0