Vulnerabilities > Microcks

DATE CVE VULNERABILITY TITLE RISK
2024-08-19 CVE-2024-44076 Unspecified vulnerability in Microcks
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
network
low complexity
microcks
critical
9.8
2023-12-04 CVE-2023-48910 Server-Side Request Forgery (SSRF) vulnerability in Microcks
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download.
network
low complexity
microcks CWE-918
critical
9.8