Nicolargo

Glances

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 25.06.2026 18:05:48
  • Zuletzt bearbeitet 26.06.2026 19:16:40

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE-2026-33533. However, the implementation silen...

  • EPSS 0.3%
  • Veröffentlicht 25.06.2026 18:04:25
  • Zuletzt bearbeitet 25.06.2026 19:58:30

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CAC...

  • EPSS 0.18%
  • Veröffentlicht 25.06.2026 18:03:43
  • Zuletzt bearbeitet 25.06.2026 19:58:30

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operato...

  • EPSS 0.21%
  • Veröffentlicht 25.06.2026 18:02:14
  • Zuletzt bearbeitet 25.06.2026 19:58:30

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/virsh.py) passes VM domain names, read directly from virsh list --all output, into f-string command t...

  • EPSS 0.16%
  • Veröffentlicht 25.06.2026 18:00:47
  • Zuletzt bearbeitet 26.06.2026 04:17:43

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTTP Host header, leaving it vulnerable to DNS rebinding attacks. An atta...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 20.04.2026 23:20:34
  • Zuletzt bearbeitet 22.04.2026 18:40:39

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values dir...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 20.04.2026 23:19:02
  • Zuletzt bearbeitet 23.04.2026 18:42:27

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation of the public_api configuration parameter. The valu...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 20.04.2026 23:09:02
  • Zuletzt bearbeitet 24.04.2026 19:09:23

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests from any origin due to a permis...

Exploit
  • EPSS 0.87%
  • Veröffentlicht 02.04.2026 14:57:51
  • Zuletzt bearbeitet 07.04.2026 14:59:46

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration parsing. This behavi...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 02.04.2026 14:56:38
  • Zuletzt bearbeitet 07.04.2026 15:01:52

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response. Because the XML-RPC handl...