CVE-2026-92569
- EPSS 0.27%
- Veröffentlicht 16.09.2026 14:40:48
- Zuletzt bearbeitet 24.09.2026 21:08:55
Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trigger outbound ...
CVE-2023-27096
- EPSS 0.61%
- Veröffentlicht 27.03.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:52:19
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController function of the Tenant Management module.
CVE-2023-27094
- EPSS 0.64%
- Veröffentlicht 23.03.2023 17:15:15
- Zuletzt bearbeitet 26.02.2025 16:15:13
An issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the tenant Management module.
CVE-2023-27095
- EPSS 0.56%
- Veröffentlicht 16.03.2023 02:15:08
- Zuletzt bearbeitet 26.02.2025 19:15:18
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.