Minder
Lfprojects · 2 CVEs
CVE-2024-27916
HIGH
`GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minde…
Mar 6, 2024
CVE-2024-27093
HIGH
Minder trusts client-provided mapping from repo name to upstream ID
Feb 26, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-27916 | `GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any authenticated user | HIGH | 0.67% | Mar 6, 2024 |
| CVE-2024-27093 | Minder trusts client-provided mapping from repo name to upstream ID | HIGH | 0.55% | Feb 26, 2024 |
Showing 1 to 2 of 2 CVEs