VYPR

CWE-610

Externally Controlled Reference to a Resource in Another Sphere

ClassDraft

Description

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-219

CVEs mapped to this weakness (245)

page 13 of 13
  • CVE-2022-39206CriSep 13, 2022
    risk 0.00cvss 9.9epss 0.02

    Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a project could use this to…

  • CVE-2021-3845HigJan 4, 2022
    risk 0.00cvss 7.5epss 0.01

    ws-scrcpy is vulnerable to External Control of File Name or Path

  • CVE-2021-43794MedDec 1, 2021
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-service. This issue is…

  • CVE-2021-32773MedJul 20, 2021
    risk 0.00cvss 6.1epss 0.01

    Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior to 8.2, code evaluated using the Racket sandbox could cause system modules to incorrectly use attacker-created modules instead of their intended dependencies.…

  • CVE-2017-16088CriJun 7, 2018
    risk 0.00cvss 10.0epss 0.03

    The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.