Known Vulnerabilities for products from Fusionauth
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Fusionauth".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-45921 json | FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be... | 7.5 - HIGH | 2022-11-28 | 2022-12-01 |
| CVE-2021-27736 json | FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromByte... | 6.5 - MEDIUM | 2021-04-22 | 2021-04-27 |
| CVE-2020-12676 json | FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion t... | 9.1 - CRITICAL | 2020-10-02 | 2021-04-30 |
| CVE-2020-7799 json | An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Setting... | 7.2 - HIGH | 2020-01-28 | 2021-07-21 |
Known software with vulnerabilities from Fusionauth
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Fusionauth | Fusionauth | 1.0.13 |