VYPR

Keti

by Eclipse

CVEs (2)

  • CVE-2021-32835CriSep 9, 2021
    risk 0.65cvss 9.9epss 0.05

    Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerability may lead to post-authentication Remote Code execution. This vulnerability is known to exist in the latest commit at the time of…

  • CVE-2021-32834HigSep 9, 2021
    risk 0.53cvss 8.2epss 0.01

    Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This…