Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2023-31056
Disclosure Date: April 24, 2023 (last updated October 08, 2023)
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.
0
Attacker Value
Unknown
CVE-2021-42776
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.
0
Attacker Value
Unknown
CVE-2021-30133
Disclosure Date: June 09, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10.
0
Attacker Value
Unknown
CVE-2021-29995
Disclosure Date: June 09, 2021 (last updated February 22, 2025)
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.
0