VYPR

Patrowlmanager

by Patrowl

Source repositories

CVEs (4)

  • CVE-2021-43828HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<owner_id>/<tmp_file> In that, owner_id…

  • CVE-2026-92753HigSep 16, 2026
    risk 0.46cvss 7.1epss

    PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.

  • CVE-2026-92754MedSep 16, 2026
    risk 0.28cvss 4.3epss

    PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including…

  • CVE-2021-43829HigDec 14, 2021
    risk 0.05cvss 7.4epss 0.59

    PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS…