CVE Browser
CVE-2024-9802 MEDIUM
Conformance validation endpoint discloses detail about service to unauthenticated users
CVSS 5.3 EPSS 0.21% Oct 10, 2024
CVE-2024-9798 MEDIUM
Health endpoint offers list of onboarded services to unauthenticated users
CVSS 5.3 EPSS 0.23% Oct 10, 2024
CVE-2024-6916 MEDIUM
Zowe CLI --show-inputs-only displays securely stored properties
CVSS 5.9 EPSS 0.14% Jul 19, 2024
CVE-2024-6834 CRITICAL
Imperative Local Command Injection allows Activity Masking
CVSS 9.0 EPSS 0.26% Jul 17, 2024
CVE-2024-6833 MEDIUM
Zowe CLI Auto-Init Leaks Credentials Locally
CVSS 6.9 EPSS 0.14% Jul 17, 2024
npm
CVE-2021-4326 HIGH
Imperative Local Command Injection allows Activity Masking
CVSS 7.8 EPSS 0.26% Feb 22, 2023
npm
CVE-2021-4314 MEDIUM
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only…
CVSS 5.3 EPSS 0.44% Jan 18, 2023
Showing 1 to 7 CVEs · page 1