VYPR

Centraldogma

by Linecorp

Source repositories

CVEs (5)

  • CVE-2019-6002MedJul 26, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-11748Jun 22, 2026
    risk 0.00cvss epss 0.01

    A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated…

  • CVE-2026-11746Jun 22, 2026
    risk 0.00cvss epss 0.00

    A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…

  • CVE-2026-11745Jun 22, 2026
    risk 0.00cvss epss 0.00

    A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored…

  • CVE-2021-38388HigSep 8, 2021
    risk 0.00cvss 8.8epss 0.01

    Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.