Olivetin

Olivetin

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 21.08.2026 23:16:26
  • Zuletzt bearbeitet 21.08.2026 23:16:26

OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, prior to commit e...

  • EPSS 0.25%
  • Veröffentlicht 29.07.2026 20:58:24
  • Zuletzt bearbeitet 30.07.2026 19:21:23

OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry output after execution without ...

  • EPSS 1%
  • Veröffentlicht 29.07.2026 20:53:09
  • Zuletzt bearbeitet 30.07.2026 19:21:23

OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument types as unsafe for Shell mode ...

  • EPSS 0.35%
  • Veröffentlicht 29.07.2026 20:43:05
  • Zuletzt bearbeitet 30.07.2026 19:21:23

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/...

  • EPSS 0.33%
  • Veröffentlicht 15.06.2026 20:13:18
  • Zuletzt bearbeitet 24.06.2026 17:17:01

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform any authentication or authorization checks. Unlike all othe...

  • EPSS 0.4%
  • Veröffentlicht 15.06.2026 19:59:27
  • Zuletzt bearbeitet 24.06.2026 17:17:01

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template engine uses a single shared text/template.Template instance (tpl package-level variable in service/internal/tpl/templates.go) across...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 11.03.2026 20:05:16
  • Zuletzt bearbeitet 17.03.2026 15:34:48

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authoriza...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 10.03.2026 21:08:53
  • Zuletzt bearbeitet 12.03.2026 18:12:18

OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution log entries to disk. The filename used for these log files is constructed in part from the ...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 06.03.2026 21:16:17
  • Zuletzt bearbeitet 12.03.2026 15:19:08

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization flaw in OliveTin allows authenticated users with view: false permission to enumerate action bindings and metadata via dashboard and ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 06.03.2026 21:16:16
  • Zuletzt bearbeitet 12.03.2026 15:46:39

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low‑privileged authenticated user to execute actions they are not permitt...