VYPR

Pluto

by Plutolang

Source repositories

CVEs (2)

  • CVE-2024-32973MedMay 1, 2024
    risk 0.24cvss 4.8epss 0.00

    Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. In affected versions an attacker with the ability to actively intercept network traffic would be able to use a specifically-crafted certificate to fool Pluto into trusting it to be the intended remote…

  • CVE-2024-45597MedSep 10, 2024
    risk 0.00cvss 5.3epss 0.00

    Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to http.request header values are affected. An attacker could use this to send arbitrary requests, potentially leveraging authentication tokens provided in the same…