Showing 2 vulnerabilities on this page for cas

Signals CISA KEV Ransomware Nuclei
jenkins vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CAS <= 1.0.0 - Unauthenticated SSRF

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

CWE-918May 23, 20241 related artifact
CVSS9.1v3.1EPSS1.82%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

CAS <= 1.0.0 - Unauthenticated Arbitrary File Access

This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server

CWE-22May 23, 2024
CVSS7.5v3.1EPSS0.719%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX