Strangebee

Thehive

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 23.05.2025 20:15:25
  • Zuletzt bearbeitet 28.05.2025 14:58:52

An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows unauthenticated remote attackers to use the password reset feature without limits. This can lead to se...

  • EPSS 0.21%
  • Veröffentlicht 23.05.2025 20:15:25
  • Zuletzt bearbeitet 28.05.2025 14:58:52

A Server-Side Request Forgery (SSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows remote authenticated attackers with admin permissions (allowing them to access speci...

  • EPSS 0.06%
  • Veröffentlicht 23.05.2025 00:00:00
  • Zuletzt bearbeitet 28.05.2025 14:58:52

A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures...

  • EPSS 0.07%
  • Veröffentlicht 23.05.2025 00:00:00
  • Zuletzt bearbeitet 28.05.2025 14:58:52

A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of t...

  • EPSS 0.24%
  • Veröffentlicht 19.01.2024 14:15:13
  • Zuletzt bearbeitet 09.06.2025 18:15:24

StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker to upload a malicious HTML file with Javascript code that will be executed in the context ...

  • EPSS 0.19%
  • Veröffentlicht 19.01.2024 14:15:13
  • Zuletzt bearbeitet 02.06.2025 15:15:31

StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious JavaScript code inside the template or its variables, that will be executed in the ...

  • EPSS 0.94%
  • Veröffentlicht 11.09.2023 23:15:07
  • Zuletzt bearbeitet 21.11.2024 08:14:43

An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.

  • EPSS 0.46%
  • Veröffentlicht 02.06.2019 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:58

An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala...