CVE-2025-57817
- EPSS 0.07%
- Veröffentlicht 08.09.2025 21:17:09
- Zuletzt bearbeitet 10.09.2025 18:41:28
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize scope assignment. This allows highly privileged users with `client:crea...
CVE-2025-57816
- EPSS 0.04%
- Veröffentlicht 08.09.2025 21:14:06
- Zuletzt bearbeitet 10.09.2025 18:42:17
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies rate limits b...
CVE-2025-57766
- EPSS 0.05%
- Veröffentlicht 08.09.2025 21:12:07
- Zuletzt bearbeitet 10.09.2025 18:44:37
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vulnerability chaining opportunity where attackers who have obtained session tok...
CVE-2025-57815
- EPSS 0.06%
- Veröffentlicht 08.09.2025 21:11:53
- Zuletzt bearbeitet 10.09.2025 18:43:41
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lacks specific anti-automation controls designed to protect against brute...
CVE-2024-52008
- EPSS 0.08%
- Veröffentlicht 26.11.2024 19:15:29
- Zuletzt bearbeitet 23.09.2025 13:43:13
Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces p...
CVE-2024-45053
- EPSS 2.29%
- Veröffentlicht 04.09.2024 16:15:07
- Zuletzt bearbeitet 06.09.2024 18:20:35
Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitization or rendering environment restrictions, allowing for Server-Side T...
CVE-2024-45052
- EPSS 0.36%
- Veröffentlicht 04.09.2024 16:15:07
- Zuletzt bearbeitet 06.09.2024 18:18:59
Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an unauthenticated attacker to determine the existenc...
CVE-2024-31223
- EPSS 7.01%
- Veröffentlicht 03.07.2024 18:15:05
- Zuletzt bearbeitet 04.09.2025 14:07:17
Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to communicate with the Fides webserver backend. The value of this variable is ...
CVE-2024-38537
- EPSS 22.23%
- Veröffentlicht 02.07.2024 20:15:05
- Zuletzt bearbeitet 02.09.2025 20:27:17
Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domain in a very limited edge case, when it detected a legacy browser such a...
CVE-2024-35189
- EPSS 0.33%
- Veröffentlicht 30.05.2024 20:15:09
- Zuletzt bearbeitet 20.10.2025 17:56:22
Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ contain sensitive data (e.g. passwords, private keys, etc.)...