Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Fleet: ORDER BY column injection on activity list endpoints | Low Risk 3.1 | 1 month ago | 8 hours ago |
|
|
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet | Unknown | 1 month ago | 8 hours ago |
|
|
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs | Medium Risk 5.3 | 1 month ago | 8 hours ago |
|
|
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet | Unknown | 1 month ago | 8 hours ago |
|
|
SAML authentication vulnerability due to stdlib XML parsing | High Risk 8.0 | 4 years ago | 18 days ago |
|
|
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet | Unknown | 1 month ago | 1 month ago |
|
|
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint | Medium Risk 6.5 | 1 month ago | 1 month ago |
|
|
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet | Unknown | 1 month ago | 1 month ago |
|
|
Fleet DM Vulnerable to Cross-Team Policy Data Exposure via Global Policy Read Endpoint | Medium Risk 4.3 | 3 months ago | 2 months ago |
|
|
Fleet DM Vulnerable to Cross-Team Policy Data Exposure via Global Policy Read Endpoint in github.com/fleetdm/fleet | Unknown | 2 months ago | 2 months ago |
|
|
Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit | High Risk 7.8 | 5 months ago | 3 months ago |
|
|
Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint | Medium Risk 6.5 | 3 months ago | 3 months ago |
|
|
Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint | Medium Risk 6.5 | 3 months ago | 3 months ago |
|
|
Fleet: IP spoofing allows bypassing API rate limiting | Medium Risk 6.0 | 4 months ago | 3 months ago |
|
|
Fleet has a rate limiting bypass via untrusted client IP headers | Medium Risk 5.3 | 4 months ago | 3 months ago |
|
|
Fleet server may terminate unexpectedly when handling certain gRPC requests | High Risk 8.0 | 4 months ago | 3 months ago |
|
|
Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint in github.com/fleetdm/fleet | Unknown | 3 months ago | 3 months ago |
|
|
Fleet server may terminate unexpectedly when handling certain gRPC requests in github.com/fleetdm/fleet | Unknown | 3 months ago | 3 months ago |
|
|
Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit in github.com/fleetdm/fleet | Unknown | 3 months ago | 3 months ago |
|
|
Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint in github.com/fleetdm/fleet | Unknown | 3 months ago | 3 months ago |
|
|
Fleet: IP spoofing allows bypassing API rate limiting in github.com/fleetdm/fleet | Unknown | 3 months ago | 3 months ago |
|
|
Fleet has a rate limiting bypass via untrusted client IP headers in github.com/fleetdm/fleet | Unknown | 3 months ago | 3 months ago |
|
|
Fleet vulnerable to OS command injection in software packages | Medium Risk 6.0 | 4 months ago | 3 months ago |
|
|
Fleet Windows MDM Azure AD JWT Authentication Bypass | High Risk 7.5 | 4 months ago | 3 months ago |
|
|
Fleet Windows MDM Azure AD JWT Authentication Bypass in github.com/fleetdm/fleet | Unknown | 3 months ago | 3 months ago |
|
|
Fleet vulnerable to OS command injection in software packages in github.com/fleetdm/fleet | Unknown | 3 months ago | 3 months ago |
|
|
Fleet has a Windows MDM management endpoint authentication bypass | High Risk 7.5 | 4 months ago | 3 months ago |
|
|
Windows MDM management endpoint authentication bypass in github.com/fleetdm/fleet/v4 | Unknown | 4 months ago | 4 months ago |
|
|
Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
Fleet's user account creation via invite does not enforce invited email address | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
A Fleet team maintainer can transfer hosts from any team via missing source team authorization | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
Fleet's unbounded request body read allows remote Denial of Service | High Risk 8.0 | 6 months ago | 5 months ago |
|
|
Fleet's Apple MDM profile delivery has second-order SQL Injection that can compromise the database | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
Fleet: Password reset tokens remain valid after password change for 24 hours | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
Fleet vulnerable to SQL Injection in MDM bootstrap package by authenticated team or global admin | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint in github.com/fleetdm/fleet | Unknown | 5 months ago | 5 months ago |
|
|
Fleet's unbounded request body read allows remote Denial of Service in github.com/fleetdm/fleet | Unknown | 5 months ago | 5 months ago |
|
|
A Fleet team maintainer can transfer hosts from any team via missing source team authorization in github.com/fleetdm/fleet | Unknown | 5 months ago | 5 months ago |
|
|
Fleet's user account creation via invite does not enforce invited email address in github.com/fleetdm/fleet | Unknown | 5 months ago | 5 months ago |
|
|
Fleet vulnerable to SQL Injection in MDM bootstrap package by authenticated team or global admin in github.com/fleetdm/fleet | Unknown | 5 months ago | 5 months ago |
|
|
Fleet: Password reset tokens remain valid after password change for 24 hours in github.com/fleetdm/fleet | Unknown | 5 months ago | 5 months ago |
|
|
Fleet's Apple MDM profile delivery has second-order SQL Injection that can compromise the database in github.com/fleetdm/fleet | Unknown | 5 months ago | 5 months ago |
|
|
Fleet: Authorization Bypass in certificate template batch deletion for team administrators | Medium Risk 6.0 | 7 months ago | 6 months ago |
|
|
Fleet: Authorization Bypass in certificate template batch deletion for team administrators in github.com/fleetdm/fleet | Unknown | 7 months ago | 6 months ago |
|
|
Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users | High Risk 8.0 | 7 months ago | 6 months ago |
|
|
Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users in github.com/fleetdm/fleet | Unknown | 7 months ago | 6 months ago |
|
|
Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint | Medium Risk 6.0 | 7 months ago | 6 months ago |
|
|
Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint in github.com/fleetdm/fleet | Unknown | 7 months ago | 6 months ago |
|
|
Fleet: Device lock PIN can be predicted if lock time is known | Medium Risk 6.0 | 7 months ago | 6 months ago |
|
|
Fleet: Device lock PIN can be predicted if lock time is known in github.com/fleetdm/fleet | Unknown | 7 months ago | 6 months ago |
Page 1