charm
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37587 | Med | 0.42 | 6.5 | 0.01 | Jul 30, 2021 | In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data. | ||
| CVE-2021-37588 | Med | 0.38 | 5.9 | 0.01 | Jul 30, 2021 | In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data. | ||
| CVE-2022-29180 | Med | 0.31 | 5.9 | 0.01 | May 7, 2022 | A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server. This has been patched and is available in release [v0.12.1](https://github.com/charmbracelet/charm/releases/tag/v0.12.1). We… |
- risk 0.42cvss 6.5epss 0.01
In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data.
- risk 0.38cvss 5.9epss 0.01
In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data.
- risk 0.31cvss 5.9epss 0.01
A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server. This has been patched and is available in release [v0.12.1](https://github.com/charmbracelet/charm/releases/tag/v0.12.1). We…