VYPR

Contributor License Agreement Assistant

by SAP

CVEs (2)

  • CVE-2023-39438HigAug 15, 2023
    risk 0.53cvss 8.1epss 0.00

    A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons…

  • CVE-2022-29617MedJun 6, 2022
    risk 0.42cvss 6.5epss 0.01

    Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application.