Vendor
Rami
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27891 | Hig | 0.49 | 7.5 | 0.01 | Mar 6, 2023 | rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1. | ||
| CVE-2023-44464 | Hig | 0.44 | 7.8 | 0.00 | Sep 29, 2023 | pretix before 2023.7.2 allows Pillow to parse EPS files. | ||
| CVE-2023-44463 | Med | 0.27 | 5.3 | 0.01 | Oct 2, 2023 | An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application. |
- risk 0.49cvss 7.5epss 0.01
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
- risk 0.44cvss 7.8epss 0.00
pretix before 2023.7.2 allows Pillow to parse EPS files.
- risk 0.27cvss 5.3epss 0.01
An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.