Known Vulnerabilities for Caldera by Mitre
Listed below are 10 of the newest known vulnerabilities associated with "Caldera" by "Mitre".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-41139 json | MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution o... | 5.4 - MEDIUM | 2022-10-17 | 2022-10-19 |
| CVE-2022-40606 json | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different v... | 6.1 - MEDIUM | 2022-10-17 | 2022-10-19 |
| CVE-2022-40605 json | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different v... | 6.1 - MEDIUM | 2022-10-17 | 2022-10-19 |
| CVE-2021-42562 json | An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having... | 8.1 - HIGH | 2022-01-12 | 2022-07-12 |
| CVE-2021-42561 json | An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python ... | 8.8 - HIGH | 2022-01-12 | 2022-07-12 |
| CVE-2021-42560 json | An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF d... | 8.8 - HIGH | 2022-01-12 | 2022-01-15 |
| CVE-2021-42559 json | An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the... | 8.8 - HIGH | 2022-01-12 | 2022-01-19 |
| CVE-2021-42558 json | An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be ex... | 6.1 - MEDIUM | 2022-01-12 | 2022-01-19 |
| CVE-2020-19907 json | A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execut... | 8.8 - HIGH | 2021-07-12 | 2022-10-18 |
| CVE-2020-14462 json | CALDERA 2.7.0 allows XSS via the Operation Name box. | 5.4 - MEDIUM | 2020-06-19 | 2020-06-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mitre | Caldera | 2.7.0 | |||
| Application | Mitre | Caldera | 2.6.6 | |||
| Application | Mitre | Caldera | 2.6.5 | |||
| Application | Mitre | Caldera | 2.6.4 | |||
| Application | Mitre | Caldera | 2.6.3 | |||
| Application | Mitre | Caldera | 2.6.2 | |||
| Application | Mitre | Caldera | 2.6.1 | |||
| Application | Mitre | Caldera | 2.6.0 | |||
| Application | Mitre | Caldera | 2.5.1 | |||
| Application | Mitre | Caldera | 2.5.0 | |||
| Application | Mitre | Caldera | 2.4.0 | |||
| Application | Mitre | Caldera | 2.3.2 | |||
| Application | Mitre | Caldera | 2.3.1 | |||
| Application | Mitre | Caldera | 2.3.0 | |||
| Application | Mitre | Caldera | 2.2.0 | |||
| Application | Mitre | Caldera | 2.1.0 | |||
| Application | Mitre | Caldera | 2.0.0 |