CWE-610
Externally Controlled Reference to a Resource in Another Sphere
Description
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-219
CVEs mapped to this weakness (245)
page 13 of 13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39206 | Cri | 0.00 | 9.9 | 0.02 | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a project could use this to… | ||
| CVE-2021-3845 | Hig | 0.00 | 7.5 | 0.01 | Jan 4, 2022 | ws-scrcpy is vulnerable to External Control of File Name or Path | ||
| CVE-2021-43794 | Med | 0.00 | 5.3 | 0.01 | Dec 1, 2021 | Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-service. This issue is… | ||
| CVE-2021-32773 | Med | 0.00 | 6.1 | 0.01 | Jul 20, 2021 | Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior to 8.2, code evaluated using the Racket sandbox could cause system modules to incorrectly use attacker-created modules instead of their intended dependencies.… | ||
| CVE-2017-16088 | Cri | 0.00 | 10.0 | 0.03 | Jun 7, 2018 | The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox. |
- risk 0.00cvss 9.9epss 0.02
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a project could use this to…
- risk 0.00cvss 7.5epss 0.01
ws-scrcpy is vulnerable to External Control of File Name or Path
- risk 0.00cvss 5.3epss 0.01
Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-service. This issue is…
- risk 0.00cvss 6.1epss 0.01
Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior to 8.2, code evaluated using the Racket sandbox could cause system modules to incorrectly use attacker-created modules instead of their intended dependencies.…
- risk 0.00cvss 10.0epss 0.03
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.