CVE-2025-54376
- EPSS 0.66%
- Veröffentlicht 10.09.2025 19:49:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an unauthenticated ...
CVE-2025-54123
- EPSS 10.54%
- Veröffentlicht 10.09.2025 18:41:46
- Zuletzt bearbeitet 17.09.2025 21:17:53
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injection vulnerability at `/api/v2/hoverfly/middleware` endpoint due to insufficient validation and sanit...
CVE-2024-45388
- EPSS 55.86%
- Veröffentlicht 02.09.2024 18:15:38
- Zuletzt bearbeitet 19.09.2024 15:18:32
Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new simulation views from the contents of a user-specified file. This feature...