VYPR
Vendor

TheHive

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2017-18376HigJun 2, 2019
    risk 0.57cvss 8.8epss 0.02

    An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.

  • CVE-2026-63099Jul 17, 2026
    risk 0.00cvss epss 0.00

    TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. Attackers can exploit the…

  • CVE-2026-63098Jul 17, 2026
    risk 0.00cvss epss 0.00

    TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the…