VYPR

Centraldogma

by Linecorp

Source repositories

CVEs (7)

  • CVE-2026-11746CriJun 22, 2026
    risk 0.61cvss epss 0.00

    A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…

  • CVE-2026-11745HigJun 22, 2026
    risk 0.57cvss epss 0.00

    A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored…

  • CVE-2024-1143CriFeb 2, 2024
    risk 0.53cvss 9.3epss 0.00

    Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.

  • CVE-2026-11748MedJun 22, 2026
    risk 0.45cvss epss 0.01

    A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated…

  • CVE-2019-6002MedJul 26, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2025-11222MedDec 4, 2025
    risk 0.33cvss 6.1epss 0.00

    Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft.

  • CVE-2021-38388HigSep 8, 2021
    risk 0.00cvss 8.8epss 0.01

    Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.