CVE-2025-54376
- EPSS 0.17%
- Veröffentlicht 10.09.2025 19:49:08
- Zuletzt bearbeitet 24.09.2025 14:18:24
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an unauthenticated ...
CVE-2025-54123
- EPSS 47.29%
- Veröffentlicht 10.09.2025 18:41:46
- Zuletzt bearbeitet 17.09.2025 21:17:53
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injection vulnerability at `/api/v2/hoverfly/middleware` endpoint due to insufficient validation and sanit...
CVE-2024-45388
- EPSS 93.68%
- Veröffentlicht 02.09.2024 18:15:38
- Zuletzt bearbeitet 19.09.2024 15:18:32
Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new simulation views from the contents of a user-specified file. This feature...