ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-31056
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed.

CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.

NVD description · AI analysis pending
6.5<1%
  • cloverdx cloverdx
CVE-2021-42776
CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.

CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.

NVD description · AI analysis pending
7.7<1%
  • cloverdx cloverdx
CVE-2021-29995
+1 in the same advisory: …30133
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (inclu

A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

NVD description · AI analysis pending
8.8
group max
4% PoC
  • cloverdx cloverdx