Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-36460 | An issue was discovered in the model crate through 2020-11-10 for Rust. An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation of the Send and Sync traits without regard for the inner type. NVD description · AI analysis pending | 8.1 | 1% | PoC |
| — | |
| CVE-2020-36255 | An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0. An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0. The Branca implementation allows an attacker to modify and forge authentication tokens. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2017-0374 +1 in the same advisory: …0373 | lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working dir lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array. NVD description · AI analysis pending | 7.8 group max | <1% |
| — |