Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2025-25069
Disclosure Date: February 07, 2025 (last updated February 08, 2025)
A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks.
Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests,
a valid HTTP request can also be sent to Kvrocks as a valid RESP request
and trigger some database operations, which can be dangerous when
it is chained with SSRF.
It is similiar to CVE-2016-10517 in Redis.
This issue affects Apache Kvrocks: from the initial version to the latest version 2.11.0.
Users are recommended to upgrade to version 2.11.1, which fixes the issue.
0
Attacker Value
Unknown
CVE-2024-44076
Disclosure Date: August 19, 2024 (last updated August 22, 2024)
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
0
Attacker Value
Unknown
CVE-2023-48910
Disclosure Date: December 04, 2023 (last updated December 08, 2023)
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
0
Attacker Value
Unknown
CVE-2019-12440
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
0
Attacker Value
Unknown
CVE-2011-4606
Disclosure Date: December 15, 2011 (last updated October 04, 2023)
Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) 3.3.0.1 allows local users to overwrite arbitrary files via a symlink attack on .rocksndiamonds/cache/artworkinfo.cache under a user's home directory.
0
Attacker Value
Unknown
CVE-2006-3693
Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system function call.
0