Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-15950

    Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.

    Last Modified: Nov 21, 2024
    Published: Nov 05, 2020

    CVE-2020-15949

    Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.

    Last Modified: Nov 21, 2024
    Published: Nov 05, 2020

    CVE-2020-15951

    Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.

    Last Modified: Nov 21, 2024
    Published: Nov 05, 2020

    CVE-2020-15952

    Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.

    Last Modified: Nov 21, 2024
    Published: Nov 05, 2020
    Items Per Page
    Immuta Vulnerabilities & Security CVEs | CVE-DB