VYPR

Microcks

by Microcks

Source repositories

CVEs (3)

  • CVE-2023-48910CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

  • CVE-2024-44076CriAug 19, 2024
    risk 0.57cvss 9.8epss 0.01

    In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.

  • CVE-2026-69110CriAug 4, 2026
    risk 0.52cvss 9.1epss 0.01

    OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints.…