Vulnerabilities
Vulnerable Software
Stackstorm:  >> Stackstorm  >> 3.7.0  Security Vulnerabilities
Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentially leading to the exposure of sensitive Information.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-06
Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pack rules to inject arbitrary script or HTML that may be executed in Web UI for other logged in users.
CVSS Score
5.4
EPSS Score
0.005
Published
2022-12-05


Contact Us

Shodan ® - All rights reserved