Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
- EPSS 0.29%
- Veröffentlicht 22.04.2026 20:31:29
- Zuletzt bearbeitet 24.04.2026 13:10:21
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler ...
9.9
CVE-2026-39842
- EPSS 0.92%
- Veröffentlicht 14.04.2026 23:21:22
- Zuletzt bearbeitet 23.04.2026 17:34:49
OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-suppli...
9.8
CVE-2022-31860
- EPSS 1.8%
- Veröffentlicht 06.09.2022 18:15:15
- Zuletzt bearbeitet 12.06.2025 14:15:29
An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.