VYPR

UI

by Kafbat

CVEs (2)

  • CVE-2023-52251HigJan 25, 2024
    risk 0.60cvss 8.8epss 0.87

    An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no commit since 2024-04-08.

  • CVE-2026-5562HigApr 5, 2026
    risk 0.47cvss 7.3epss 0.02

    A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code injection. The attack can be initiated remotely. The exploit is…