Ethyca

Fides

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 08.06.2026 20:01:54
  • Zuletzt bearbeitet 09.06.2026 15:25:56

Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.

  • EPSS 0.31%
  • Veröffentlicht 12.05.2026 17:29:22
  • Zuletzt bearbeitet 13.05.2026 18:24:31

Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can...

  • EPSS 0.39%
  • Veröffentlicht 08.09.2025 21:17:09
  • Zuletzt bearbeitet 10.09.2025 18:41:28

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize scope assignment. This allows highly privileged users with `client:crea...

  • EPSS 0.41%
  • Veröffentlicht 08.09.2025 21:14:06
  • Zuletzt bearbeitet 10.09.2025 18:42:17

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies rate limits b...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 08.09.2025 21:12:07
  • Zuletzt bearbeitet 10.09.2025 18:44:37

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vulnerability chaining opportunity where attackers who have obtained session tok...

  • EPSS 0.28%
  • Veröffentlicht 08.09.2025 21:11:53
  • Zuletzt bearbeitet 10.09.2025 18:43:41

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lacks specific anti-automation controls designed to protect against brute...

  • EPSS 0.54%
  • Veröffentlicht 26.11.2024 19:15:29
  • Zuletzt bearbeitet 23.09.2025 13:43:13

Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces p...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 04.09.2024 16:15:07
  • Zuletzt bearbeitet 06.09.2024 18:20:35

Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitization or rendering environment restrictions, allowing for Server-Side T...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 04.09.2024 16:15:07
  • Zuletzt bearbeitet 06.09.2024 18:18:59

Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an unauthenticated attacker to determine the existenc...

Exploit
  • EPSS 1.11%
  • Veröffentlicht 03.07.2024 18:15:05
  • Zuletzt bearbeitet 04.09.2025 14:07:17

Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to communicate with the Fides webserver backend. The value of this variable is ...