Vulnerabilities > Irods

DATE CVE VULNERABILITY TITLE RISK
2024-06-16 CVE-2024-38461 Improper Check for Unusual or Exceptional Conditions vulnerability in Irods 4.1.10/4.2.0
irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.
network
low complexity
irods CWE-754
7.5
2024-06-16 CVE-2024-38462 Unspecified vulnerability in Irods 4.1.10/4.2.0
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.
network
low complexity
irods
critical
9.8
2017-05-05 CVE-2017-8799 OS Command Injection vulnerability in Irods 4.1.10/4.2.0
Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remote shell commands via iRODS virtual pathnames.
network
low complexity
irods CWE-78
critical
9.8