Zowe
Open Mainframe Project · 6 CVEs
CVE-2024-9802
MEDIUM
Conformance validation endpoint discloses detail about service to unauthenticated users
Oct 10, 2024
CVE-2024-9798
MEDIUM
Health endpoint offers list of onboarded services to unauthenticated users
Oct 10, 2024
CVE-2024-6834
CRITICAL
Imperative Local Command Injection allows Activity Masking
Jul 17, 2024
CVE-2024-6833
MEDIUM
Zowe CLI Auto-Init Leaks Credentials Locally
Jul 17, 2024
CVE-2021-4326
HIGH
Imperative Local Command Injection allows Activity Masking
Feb 22, 2023
CVE-2021-4314
MEDIUM
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT t…
Jan 18, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-9802 | Conformance validation endpoint discloses detail about service to unauthenticated users | MEDIUM | 0.21% | Oct 10, 2024 |
| CVE-2024-9798 | Health endpoint offers list of onboarded services to unauthenticated users | MEDIUM | 0.23% | Oct 10, 2024 |
| CVE-2024-6834 | Imperative Local Command Injection allows Activity Masking | CRITICAL | 0.26% | Jul 17, 2024 |
| CVE-2024-6833 | Zowe CLI Auto-Init Leaks Credentials Locally | MEDIUM | 0.14% | Jul 17, 2024 |
| CVE-2021-4326 | Imperative Local Command Injection allows Activity Masking | HIGH | 0.26% | Feb 22, 2023 |
| CVE-2021-4314 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only… | MEDIUM | 0.44% | Jan 18, 2023 |
Showing 1 to 6 of 6 CVEs