CVE-2026-92783
- EPSS 0.37%
- Veröffentlicht 16.09.2026 20:32:40
- Zuletzt bearbeitet 23.09.2026 17:17:49
Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners o...
CVE-2024-46507
- EPSS 3.92%
- Veröffentlicht 08.05.2026 00:00:00
- Zuletzt bearbeitet 08.05.2026 19:52:49
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.
CVE-2024-46508
- EPSS 0.43%
- Veröffentlicht 08.05.2026 00:00:00
- Zuletzt bearbeitet 08.05.2026 19:58:25
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).
CVE-2024-45412
- EPSS 0.78%
- Veröffentlicht 10.09.2024 16:15:20
- Zuletzt bearbeitet 21.11.2024 09:37:44
Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode normalization with a compatibility form NFKD. Under Windows, such normalization ...