Microcks
by Microcks
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-48910 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2023 | Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request. | ||
| CVE-2024-44076 | Cri | 0.57 | 9.8 | 0.01 | Aug 19, 2024 | In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access. | ||
| CVE-2026-69110 | Cri | 0.52 | 9.1 | 0.01 | Aug 4, 2026 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints.… |
- risk 0.64cvss 9.8epss 0.01
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
- risk 0.57cvss 9.8epss 0.01
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
- risk 0.52cvss 9.1epss 0.01
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints.…