Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Eriner

#17618of 53,624
15.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-24206
8.8
2021-12-16
Home Assistant · Home Assistant Community Add-On: Ssh & Web Terminal · CVE-2021-45099
Name of the Vulnerable Software and Affected Versions: Home Assistant Community Add-on: SSH & Web Terminal versions prior to 10.0.0 Description: The addon.stdin service has an attack surface that requires social engineering. Although the vendor does not agree that this is a vulnerability, addon.stdin was removed as a defense-in-depth measure against complex social engineering situations. Recommendations: For versions prior to 10.0.0, consider removing or disabling the addon.stdin service as a defense-in-depth measure against complex social engineering situations.
PT-2020-8679
6.5
2020-04-09
Argo · Argo · CVE-2018-21034
**Name of the Vulnerable Software and Affected Versions** Argo versions prior to v1.5.0-rc1 **Description** The issue allows authenticated Argo users to submit API calls to retrieve secrets and other manifests stored within git. **Recommendations** For versions prior to v1.5.0-rc1, update to version v1.5.0-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information stored within git until the update is applied.