Knime

Business Hub

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 08.12.2025 09:34:45
  • Zuletzt bearbeitet 27.02.2026 03:38:57

A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved int...

  • EPSS 0.03%
  • Veröffentlicht 02.10.2025 13:15:31
  • Zuletzt bearbeitet 08.10.2025 17:17:38

Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user's team. Starting with KNIME Business Hub 1.16.0 only metadata of jobs is shown to team members. Only the creator of a job can see ...

  • EPSS 0.04%
  • Veröffentlicht 02.10.2025 13:15:31
  • Zuletzt bearbeitet 08.10.2025 17:17:13

An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub installation which, when opened by the user, redirects the user to a page o...

  • EPSS 0.28%
  • Veröffentlicht 31.03.2025 07:15:19
  • Zuletzt bearbeitet 08.10.2025 17:18:01

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to ...

  • EPSS 0.5%
  • Veröffentlicht 31.03.2025 07:15:18
  • Zuletzt bearbeitet 08.10.2025 17:16:33

A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and ...

  • EPSS 0.33%
  • Veröffentlicht 26.03.2025 21:15:23
  • Zuletzt bearbeitet 08.10.2025 17:19:11

KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete takeover of the Kubernetes cluster is possible. Since the affected comp...

  • EPSS 0.88%
  • Veröffentlicht 09.07.2024 14:15:04
  • Zuletzt bearbeitet 08.10.2025 17:11:10

A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It allows an authenticated attacker with job execution privileges to execute a job that causes internal messages to pile up until ther...

  • EPSS 0.15%
  • Veröffentlicht 07.06.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 08:16:32

Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME Business Hub before 1.4.0 has left users vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a ...

  • EPSS 0.42%
  • Veröffentlicht 07.06.2023 09:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:47

The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about the application such as versions, host names, or IP addresses. No personal information or application data was exposed.