Yeti-platform

Yeti

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 16.09.2026 20:32:40
  • Zuletzt bearbeitet 23.09.2026 17:17:49

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners o...

Exploit
  • EPSS 3.92%
  • Veröffentlicht 08.05.2026 00:00:00
  • Zuletzt bearbeitet 08.05.2026 19:52:49

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 08.05.2026 00:00:00
  • Zuletzt bearbeitet 08.05.2026 19:58:25

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

Exploit
  • EPSS 0.78%
  • Veröffentlicht 10.09.2024 16:15:20
  • Zuletzt bearbeitet 21.11.2024 09:37:44

Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode normalization with a compatibility form NFKD. Under Windows, such normalization ...