Centraldogma
by Linecorp
Source repositories
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-11746 | Cri | 0.61 | — | 0.00 | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the… | ||
| CVE-2026-11745 | Hig | 0.57 | — | 0.00 | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored… | ||
| CVE-2024-1143 | Cri | 0.53 | 9.3 | 0.00 | Feb 2, 2024 | Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass. | ||
| CVE-2026-11748 | Med | 0.45 | — | 0.01 | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated… | ||
| CVE-2019-6002 | Med | 0.40 | 6.1 | 0.01 | Jul 26, 2019 | Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2025-11222 | Med | 0.33 | 6.1 | 0.00 | Dec 4, 2025 | Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft. | ||
| CVE-2021-38388 | Hig | 0.00 | 8.8 | 0.01 | Sep 8, 2021 | Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project. |
- risk 0.61cvss —epss 0.00
A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…
- risk 0.57cvss —epss 0.00
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored…
- risk 0.53cvss 9.3epss 0.00
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.
- risk 0.45cvss —epss 0.01
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated…
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.33cvss 6.1epss 0.00
Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft.
- risk 0.00cvss 8.8epss 0.01
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.