|
198411
|
5.3 |
MEDIUM
Network
|
hashicorp
|
vault
|
HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-35177
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198412
|
6.5 |
MEDIUM
Network
|
zimbra
|
collaboration
|
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has…
|
CWE-611
XXE
|
CVE-2020-35123
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198413
|
9.8 |
CRITICAL
Network
|
docker
|
memcached_docker_image
|
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35197
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198414
|
9.8 |
CRITICAL
Network
|
docker
|
rabbitmq_docker_image
|
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35196
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198415
|
9.8 |
CRITICAL
Network
|
docker
|
haproxy_docker_image
|
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the dock…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35195
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198416
|
9.8 |
CRITICAL
Network
|
hashicorp
|
vault
|
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote a…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35192
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198417
|
9.8 |
CRITICAL
Network
|
drupal
|
drupal_docker_images
|
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the do…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35191
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198418
|
9.8 |
CRITICAL
Network
|
plone
|
plone
|
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of t…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35190
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198419
|
9.8 |
CRITICAL
Network
|
docker
|
adminer
|
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35186
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198420
|
9.8 |
CRITICAL
Network
|
docker
|
composer_docker_image
|
The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a rem…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35184
|
2024-11-21 14:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|