VYPR

Keti

by Eclipse

CVEs (2)

  • CVE-2021-32835Sep 9, 2021
    risk 0.00cvss epss 0.04

    Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerability may lead to post-authentication Remote Code execution. This vulnerability is known to exist in the latest commit at the time of…

  • CVE-2021-32834Sep 9, 2021
    risk 0.00cvss epss 0.01

    Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This…