Olivetin

Olivetin

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 06.03.2026 21:16:16
  • Zuletzt bearbeitet 12.03.2026 15:57:33

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions when a user logs out. Although the browser cookie is cleared, the corresponding session remains valid i...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 06.03.2026 21:16:16
  • Zuletzt bearbeitet 12.03.2026 16:05:52

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public key) or "authJwtHmacSecret" (HMAC secret), the configured au...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 05.03.2026 19:34:53
  • Zuletzt bearbeitet 10.03.2026 15:29:58

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to terminate running actions through KillAction even when authRequireGuestsToLogin: true is enabled. Guests ...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 05.03.2026 19:33:46
  • Zuletzt bearbeitet 10.03.2026 15:42:11

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 login flow. Concurrent requests to /oauth/login can trigger unsynchron...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 05.03.2026 19:33:44
  • Zuletzt bearbeitet 10.03.2026 15:43:24

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation by sending concurrent password hashing requests. By...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 25.02.2026 03:16:06
  • Zuletzt bearbeitet 27.02.2026 18:58:46

OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dangerous argument types but not `password`. A user sup...

Exploit
  • EPSS 1.3%
  • Veröffentlicht 13.08.2025 00:00:00
  • Zuletzt bearbeitet 17.10.2025 17:58:09

OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.