Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-41845 | A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions are 10.9.000032 through 11.0.000006. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2021-34679 | Thycotic Password Reset Server before 5.3.0 allows credential disclosure. Thycotic Password Reset Server before 5.3.0 allows credential disclosure. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2019-18355 | An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7. An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2017-11725 | The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections. The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections. NVD description · AI analysis pending | 5.4 | <1% |
| — |