Runzero

Runzero Platform

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 07.04.2026 14:12:42
  • Zuletzt bearbeitet 21.04.2026 15:40:40

An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC...

  • EPSS 0.18%
  • Veröffentlicht 07.04.2026 14:12:32
  • Zuletzt bearbeitet 21.04.2026 15:39:43

An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/...

  • EPSS 0.17%
  • Veröffentlicht 07.04.2026 14:12:23
  • Zuletzt bearbeitet 21.04.2026 15:37:26

An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C...

  • EPSS 0.17%
  • Veröffentlicht 07.04.2026 14:12:15
  • Zuletzt bearbeitet 21.04.2026 15:36:01

An issue that could expose task information outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N (2.2 ...

  • EPSS 0.2%
  • Veröffentlicht 07.04.2026 14:12:05
  • Zuletzt bearbeitet 21.04.2026 15:34:22

An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3...

  • EPSS 0.12%
  • Veröffentlicht 07.04.2026 14:11:53
  • Zuletzt bearbeitet 21.04.2026 15:33:01

An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/P...

  • EPSS 0.19%
  • Veröffentlicht 07.04.2026 14:11:42
  • Zuletzt bearbeitet 21.04.2026 15:31:45

An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N...

  • EPSS 0.21%
  • Veröffentlicht 07.04.2026 14:11:30
  • Zuletzt bearbeitet 21.04.2026 15:22:27

An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE-613: Insufficient Control of Resources After Expiration or Release, and has an estimated CVSS score ...

  • EPSS 0.2%
  • Veröffentlicht 07.04.2026 14:11:14
  • Zuletzt bearbeitet 21.04.2026 15:11:39

An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to an Unauthorized Actor, and has an estimated CVSS sco...

  • EPSS 0.21%
  • Veröffentlicht 07.04.2026 14:10:36
  • Zuletzt bearbeitet 21.04.2026 15:10:18

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:...