Fleetdm

Fleet

29 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 26.02.2026 00:16:23
  • Zuletzt bearbeitet 02.03.2026 15:45:35

Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL expressions via the `order_key` query parameter. Due to unsafe use of `goqu.I()` when const...

  • EPSS 0.23%
  • Veröffentlicht 21.01.2026 21:50:47
  • Zuletzt bearbeitet 27.02.2026 16:14:59

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not prope...

  • EPSS 0.25%
  • Veröffentlicht 21.01.2026 21:45:34
  • Zuletzt bearbeitet 27.02.2026 16:16:14

Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenticated users to access debug and profiling endpoints regardless of role. As a result, low-pr...

  • EPSS 0.21%
  • Veröffentlicht 21.01.2026 21:18:26
  • Zuletzt bearbeitet 18.02.2026 15:31:03

fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authenti...

  • EPSS 0.62%
  • Veröffentlicht 06.03.2025 19:15:27
  • Zuletzt bearbeitet 15.04.2026 00:35:42

fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-...

  • EPSS 0.79%
  • Veröffentlicht 18.04.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:12

fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accou...

  • EPSS 0.88%
  • Veröffentlicht 04.02.2022 23:15:15
  • Zuletzt bearbeitet 21.11.2024 06:48:54

fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in two specific cases: 1. A malicio...

  • EPSS 1.94%
  • Veröffentlicht 10.02.2021 20:15:15
  • Zuletzt bearbeitet 21.11.2024 05:47:57

Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live...

  • EPSS 2.17%
  • Veröffentlicht 17.12.2020 20:15:13
  • Zuletzt bearbeitet 21.11.2024 05:19:44

Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unverified log...