Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fábio Freitas

Researcher fromCheckmarx's CxSCA group
#14864of 53,635
18.1Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2021-18165
10
2021-05-24
Unknown · @Ronomon/Opened · CVE-2021-29300
Name of the Vulnerable Software and Affected Versions: @ronomon/opened versions prior to 1.5.2 Description: The issue allows a remote attacker to execute commands on the system if the library is used with untrusted input. This is a command injection vulnerability. Recommendations: For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing all input to prevent command injection attacks. Restrict access to the library when handling untrusted input to minimize the risk of exploitation.
PT-2020-20300
8.1
2020-09-14
Dataiku · Dataiku Dss · CVE-2020-8817
**Name of the Vulnerable Software and Affected Versions** Dataiku DSS versions prior to 6.0.5 **Description** The issue allows attackers to gain write access to a project, enabling them to modify the `Created by` metadata. **Recommendations** For versions prior to 6.0.5, update to version 6.0.5 or later to resolve the issue.