{"resultsPerPage":41,"startIndex":0,"totalResults":41,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-08T05:31:10.087","vulnerabilities":[{"cve":{"id":"CVE-2007-2815","sourceIdentifier":"cve@mitre.org","published":"2007-05-22T19:30:00.000","lastModified":"2026-06-16T22:40:29.520","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The \"hit-highlighting\" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw."},{"lang":"es","value":"La funcionalidad \"hit-highlighting\" en la biblioteca webhits.dll en el Servidor web versión 5.0 de Internet Information Services (IIS) de Microsoft solo usa la configuración ACL de Windows NT, lo que permite a los atacantes remotos omitir los mecanismos de autenticación básicos y NTLM y acceder a los directorios web privados por medio del parámetro CiWebhitsfile en null.htw."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-264"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*","matchCriteriaId":"413C07EA-139F-4B7D-A58B-835BD2591FA0"}]}]}],"references":[{"url":"http://osvdb.org/41091","source":"cve@mitre.org"},{"url":"http://securityreason.com/securityalert/2725","source":"cve@mitre.org"},{"url":"http://support.microsoft.com/kb/328832","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/archive/1/469238/100/0/threaded","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/24105","source":"cve@mitre.org"},{"url":"http://osvdb.org/41091","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://securityreason.com/securityalert/2725","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://support.microsoft.com/kb/328832","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/archive/1/469238/100/0/threaded","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/24105","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2016-3387","sourceIdentifier":"secure@microsoft.com","published":"2016-10-14T02:59:23.727","lastModified":"2026-06-17T00:45:35.893","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka \"Microsoft Browser Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-3388."},{"lang":"es","value":"Microsoft Internet Explorer 10 y 11 y Microsoft Edge no restringe adecuadamente el acceso a espacios de nombres privados, lo que permite a atacantes remotos obtener privilegios a través de vectores no especificados, vulnerabilidad también conocida como \"Microsoft Browser Elevation of Privilege Vulnerability\", una vulnerabilidad diferente a CVE-2016-3388."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-264"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*","matchCriteriaId":"77D197D7-57FB-4898-8C70-B19D5F0D5BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*","matchCriteriaId":"D5808661-A082-4CBE-808C-B253972487B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*","matchCriteriaId":"D7809F78-8D56-4925-A8F9-4119B973A667"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/93381","source":"secure@microsoft.com"},{"url":"http://www.securitytracker.com/id/1036992","source":"secure@microsoft.com"},{"url":"http://www.securitytracker.com/id/1036993","source":"secure@microsoft.com"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118","source":"secure@microsoft.com"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119","source":"secure@microsoft.com"},{"url":"https://www.exploit-db.com/exploits/40607/","source":"secure@microsoft.com"},{"url":"http://www.securityfocus.com/bid/93381","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1036992","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1036993","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/40607/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2016-3388","sourceIdentifier":"secure@microsoft.com","published":"2016-10-14T02:59:24.930","lastModified":"2026-06-17T00:45:36.003","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka \"Microsoft Browser Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-3387."},{"lang":"es","value":"Microsoft Internet Explorer 10 y 11 y Microsoft Edge no restringe adecuadamente el acceso a espacios de nombres privados, lo que permite a atacantes remotos obtener privilegios a través de vectores no especificados, vulnerabilidad también conocida como \"Microsoft Browser Elevation of Privilege Vulnerability\", una vulnerabilidad diferente a CVE-2016-3387."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-264"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*","matchCriteriaId":"8BD5B232-95EA-4F8E-8C7D-7976877AD243"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*","matchCriteriaId":"D5808661-A082-4CBE-808C-B253972487B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*","matchCriteriaId":"15BAAA8C-7AF1-46CE-9FFB-3A498508A1BF"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/93382","source":"secure@microsoft.com"},{"url":"http://www.securitytracker.com/id/1036992","source":"secure@microsoft.com"},{"url":"http://www.securitytracker.com/id/1036993","source":"secure@microsoft.com"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118","source":"secure@microsoft.com"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119","source":"secure@microsoft.com"},{"url":"https://www.exploit-db.com/exploits/40606/","source":"secure@microsoft.com"},{"url":"http://www.securityfocus.com/bid/93382","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1036992","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1036993","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/40606/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2017-15882","sourceIdentifier":"cve@mitre.org","published":"2017-10-26T05:29:00.263","lastModified":"2026-06-17T01:08:25.750","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The London Trust Media Private Internet Access (PIA) application before 1.3.3.1 for Android allows remote attackers to cause a denial of service (application crash) via a large VPN server-list file."},{"lang":"es","value":"La aplicaciÃ³n London Trust Media Private Internet Access (PIA), en versiones anteriores a la 1.3.3.1 para Android permite que atacantes remotos provoquen una denegaciÃ³n de servicio (cierre inesperado de la aplicaciÃ³n) mediante un archivo de lista de servidores VPN de gran tamaÃ±o."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access:*:*:*:*:*:android:*:*","versionEndExcluding":"1.3.3.1","matchCriteriaId":"D7E8E29D-D58B-48D9-8CD4-CFCD25C9C500"}]}]}],"references":[{"url":"https://wwws.nightwatchcybersecurity.com/2017/10/25/advisory-pia-android-app-cve-2017-15882/","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://wwws.nightwatchcybersecurity.com/2017/10/25/advisory-pia-android-app-cve-2017-15882/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-10190","sourceIdentifier":"cve@mitre.org","published":"2018-04-17T20:29:00.473","lastModified":"2026-06-17T01:33:38.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run executable files with elevated privileges. The vulnerability is due to insufficient implementation of access controls. The \"Changelog\" and \"Help\" options available from the system tray context menu spawn an elevated instance of the user's default web browser. An attacker could exploit this vulnerability by selecting \"Run as Administrator\" from the context menu of an executable file within the file browser of the spawned default web browser. This may allow the attacker to execute privileged commands on the targeted system."},{"lang":"es","value":"Una vulnerabilidad en London Trust Media Private Internet Access (PIA) VPN Client v77 para Windows podría permitir que un atacante local no autenticado ejecute archivos con privilegios elevados. Esta vulnerabilidad se debe a una implementación de controles de acceso insuficiente. Las opciones \"Changelog\" y \"Help\" disponibles del menú contextual de la bandeja generan una instancia elevada del navegador web por defecto del usuario. Un atacante podría explotar esta vulnerabilidad seleccionando \"Run as Administrator\" del menú contextual de un archivo ejecutable en el navegador de archivos del navegador web generado por defecto. Esto podría permitir que el atacante ejecute comandos privilegiados en el sistema objetivo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access:77:*:*:*:*:windows:*:*","matchCriteriaId":"742CF903-900F-478E-A93B-79240FBDD66E"}]}]}],"references":[{"url":"https://github.com/VerSprite/research/blob/master/advisories/VS-2018-019.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://github.com/VerSprite/research/blob/master/advisories/VS-2018-019.md","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12572","sourceIdentifier":"cve@mitre.org","published":"2019-06-21T18:15:09.857","lastModified":"2026-06-17T02:14:53.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. On startup, the PIA Windows service (pia-service.exe) loads the OpenSSL library from %PROGRAMFILES%\\Private Internet Access\\libeay32.dll. This library attempts to load the C:\\etc\\ssl\\openssl.cnf configuration file which does not exist. By default on Windows systems, authenticated users can create directories under C:\\. A low privileged user can create a C:\\etc\\ssl\\openssl.cnf configuration file to load a malicious OpenSSL engine library resulting in arbitrary code execution as SYSTEM when the service starts."},{"lang":"es","value":"Una vulnerabilidad en el Cliente VPN versión 1.0.2 (build 02363) de Media Private Internet Access (PIA) de London Trust para Windows, podría permitir a un atacante local autenticado ejecutar código arbitrario con privilegios elevados. En el inicio, el servicio Windows PIA (pia-service.exe) carga la biblioteca OpenSSL desde %PROGRAMFILES%\\Private Internet Access\\libeay32.dll. Esta biblioteca intenta cargar el archivo de configuración C:\\etc\\ssl\\openssl.cnf que no existe. Por defecto, en los sistemas Windows, los usuarios autenticados pueden crear directorios en C:\\. Un usuario poco privilegiado puede crear un archivo de configuración C:\\etc\\ssl\\openssl.cnf para cargar una biblioteca del motor OpenSSL maliciosa, que resulta en la ejecución de código arbitrario como SYSTEM cuando el servicio se inicia."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-427"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access:1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"17C84453-C0B6-405B-91CD-EC82D9C10B56"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://blog.mirch.io/2019/06/10/cve-2019-12572-pia-windows-privilege-escalation-malicious-openssl-engine/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12572.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://blog.mirch.io/2019/06/10/cve-2019-12572-pia-windows-privilege-escalation-malicious-openssl-engine/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12572.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12571","sourceIdentifier":"cve@mitre.org","published":"2019-07-11T20:15:12.803","lastModified":"2026-06-17T02:14:53.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, local attacker to overwrite arbitrary files. When the client initiates a connection, the XML /tmp/pia-watcher.plist file is created. If the file exists, it will be truncated and the contents completely overwritten. This file is removed on disconnect. An unprivileged user can create a hard or soft link to arbitrary files owned by any user on the system, including root. This creates a denial of service condition and possible data loss if leveraged by a malicious local user."},{"lang":"es","value":"Una vulnerabilidad en el cliente VPN de Private Internet Access (PIA) versión 0.9.8 (build 02099) de London Trust Media para macOS, podría permitir que un atacante local autenticado sobrescriba archivos arbitrarios. Cuando el cliente inicia una conexión, se crea el archivo XML /tmp/pia-watcher.plist. Si el archivo existe, se truncará y el contenido se sobrescribirá por completo. Este archivo se elimina al desconectarse. Un usuario sin privilegios puede crear un enlace físico o de software a archivos arbitrarios propiedad de cualquier usuario en el sistema, incluida la root. Esto crea una condición de denegación de servicio y una posible pérdida de datos si es aprovechada por un usuario local malicioso."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:C/A:C","baseScore":6.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":9.2,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-59"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access_vpn_client:0.9.8:beta:*:*:*:*:*:*","matchCriteriaId":"E895D4BA-83E4-47B8-B575-1D7B23C2569E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"}]}]}],"references":[{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12571.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12571.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12573","sourceIdentifier":"cve@mitre.org","published":"2019-07-11T20:15:12.867","lastModified":"2026-06-17T02:14:53.610","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log option, which accepts a path as an argument. This parameter is not sanitized, which allows a local unprivileged user to overwrite arbitrary files owned by any user on the system, including root. This creates a denial of service condition and possible data loss if leveraged by a malicious local user."},{"lang":"es","value":"Una vulnerabilidad en el cliente VPN de Private Internet Access (PIA) de London Trust Media para Linux y macOS, podría permitir que un atacante local autenticado sobrescriba archivos arbitrarios. El binario openvpn_launcher es root setuid. Este binario admite la opción --log, que acepta una ruta (path) de acceso como argumento. Este parámetro no está saneado, lo que permite a un usuario local sin privilegios sobrescribir archivos arbitrarios propiedad de cualquier usuario en el sistema, incluida la root. Esto crea una condición de denegación de servicio y una posible pérdida de datos si es aprovechada por un usuario local malicioso."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:C/A:C","baseScore":6.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":9.2,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-59"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access_vpn_client:82:*:*:*:*:*:*:*","matchCriteriaId":"23845C1B-3AC7-426E-92C5-9EE5CAC42B68"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}],"references":[{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12573.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12573.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12574","sourceIdentifier":"cve@mitre.org","published":"2019-07-11T20:15:12.927","lastModified":"2026-06-17T02:14:53.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability during the software update process. The updater loads several libraries from a folder that authenticated users have write access to. A low privileged user can leverage this vulnerability to execute arbitrary code as SYSTEM."},{"lang":"es","value":"Una vulnerabilidad en el cliente VPN de Private Internet Access (PIA) versiones 1.0 de London Trust Media para Windows, podría permitir a un atacante local autenticado ejecutar código arbitrario con privilegios elevados. El cliente PIA es susceptible a una vulnerabilidad de inyección DLL durante el proceso de actualización de software. El actualizador carga varias bibliotecas desde una carpeta a la que los usuarios autenticados tienen acceso de escritura. Un usuario con pocos privilegios puede aprovechar esta vulnerabilidad para ejecutar código arbitrario como SYSTEM."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-426"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access_vpn_client:1.0:*:*:*:*:*:*:*","matchCriteriaId":"7A156499-0748-4441-872C-3987A5FC4925"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12574.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12574.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12575","sourceIdentifier":"cve@mitre.org","published":"2019-07-11T20:15:12.990","lastModified":"2026-06-17T02:14:53.853","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby, which in turn attempts to load several libraries under /tmp/ruby-deploy.old/lib. A local unprivileged user can create a malicious library under this path to execute arbitrary code as the root user."},{"lang":"es","value":"Una vulnerabilidad en el cliente VPN de Private Internet Access (PIA) de London Trust Media para Linux, podría permitir a un atacante local autenticado ejecutar código arbitrario con privilegios elevados. El binario root_runner.64 es root setuid. Este binario ejecuta el archivo /opt/pia/ruby/64/ruby, que a su vez intenta cargar varias bibliotecas en /tmp/ruby-deploy.old/lib. Un usuario local sin privilegios puede crear una biblioteca maliciosa bajo esta ruta (path) de acceso para ejecutar código arbitrario como el usuario root."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-427"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access_vpn_client:82:*:*:*:*:*:*:*","matchCriteriaId":"23845C1B-3AC7-426E-92C5-9EE5CAC42B68"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}],"references":[{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12575.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12575.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12576","sourceIdentifier":"cve@mitre.org","published":"2019-07-11T20:15:13.053","lastModified":"2026-06-17T02:14:53.977","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating system utilities to configure the system. The networksetup utility is called using relative paths. A local unprivileged user can execute arbitrary commands as root by creating a networksetup trojan which will be executed during the connection process. This is possible because the PATH environment variable is not reset prior to executing the OS utility."},{"lang":"es","value":"Una vulnerabilidad en el cliente VPN de Private Internet Access (PIA) de London Trust Media para macOS, podría permitir a un atacante local autenticado ejecutar código arbitrario con privilegios elevados. El binario openvpn_launcher es root setuid. Este programa se llama durante el proceso de conexión y ejecuta varias utilidades del sistema operativo para configurar el sistema. La utilidad networksetup se llama mediante rutas (path) relativas. Un usuario local sin privilegios puede ejecutar comandos arbitrarios como root mediante la creación de un troyano networksetup que se ejecutará durante el proceso de conexión. Esto es posible porque la variable de entorno PATH no se restablece antes de ejecutar la utilidad del sistema operativo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-426"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access_vpn_client:82:*:*:*:*:*:*:*","matchCriteriaId":"23845C1B-3AC7-426E-92C5-9EE5CAC42B68"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"}]}]}],"references":[{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12576.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12576.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12577","sourceIdentifier":"cve@mitre.org","published":"2019-07-11T20:15:13.117","lastModified":"2026-06-17T02:14:54.103","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS binary openvpn_launcher.64 is setuid root. This binary creates /tmp/pia_upscript.sh when executed. Because the file creation mask (umask) is not reset, the umask value is inherited from the calling process. This value can be manipulated to cause the privileged binary to create files with world writable permissions. A local unprivileged user can modify /tmp/pia_upscript.sh during the connect process to execute arbitrary code as the root user."},{"lang":"es","value":"Una vulnerabilidad en el cliente VPN de Private Internet Access (PIA) de London Trust Media para macOS, podría permitir a un atacante local autenticado ejecutar código arbitrario con privilegios elevados. El binario de macOS openvpn_launcher.64 es root setuid. Este binario crea el archivo /tmp/pia_upscript.sh cuando es ejecutado. Dado que la máscara de creación de archivos (umask) no se restablece, el valor umask se hereda del proceso de llamada. Este valor se puede manipular para causar que el binario con privilegios cree archivos con permisos de escritura mundial. Un usuario local sin privilegios puede modificar el archivo /tmp/pia_upscript.sh durante el proceso de conexión para ejecutar código arbitrario como el usuario root."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access_vpn_client:82:*:*:*:*:*:*:*","matchCriteriaId":"23845C1B-3AC7-426E-92C5-9EE5CAC42B68"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"}]}]}],"references":[{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12577.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12577.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12578","sourceIdentifier":"cve@mitre.org","published":"2019-07-11T20:15:13.193","lastModified":"2026-06-17T02:14:54.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. This binary executes /opt/pia/openvpn-64/openvpn, passing the parameters provided from the command line. Care was taken to programmatically disable potentially dangerous openvpn parameters; however, the --route-pre-down parameter can be used. This parameter accepts an arbitrary path to a script/program to be executed when OpenVPN exits. The --script-security parameter also needs to be passed to allow for this action to be taken, and --script-security is not currently in the disabled parameter list. A local unprivileged user can pass a malicious script/binary to the --route-pre-down option, which will be executed as root when openvpn is stopped."},{"lang":"es","value":"Una vulnerabilidad en el cliente VPN de Private Internet Access (PIA) de London Trust Media para Linux, podría permitir a un atacante local autenticado ejecutar código arbitrario con privilegios elevados. El binario openvpn_launcher.64 es root setuid. Este binario ejecuta el archivo /opt/pia/openvpn-64/openvpn, pasando los parámetros proporcionados desde la línea de comandos. Se tuvo cuidado de desactivar mediante programación los parámetros openvpn potencialmente peligrosos; sin embargo, puede ser utilizado el parámetro --route-pre-down. Este parámetro acepta una ruta (path) arbitraria en un script/programa que se ejecutará cuando se cierre OpenVPN. El parámetro --script-security también debe pasarse para permitir que se tome esta acción y --script-security no está actualmente en la lista de parámetros deshabilitados. Un usuario local sin privilegios puede pasar un script/binario malicioso a la opción --route-pre-down, que será ejecutado como root cuando se detenga openvpn."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-88"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access_vpn_client:82:*:*:*:*:*:*:*","matchCriteriaId":"23845C1B-3AC7-426E-92C5-9EE5CAC42B68"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}],"references":[{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12578.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12578.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-12579","sourceIdentifier":"cve@mitre.org","published":"2019-07-11T20:15:13.240","lastModified":"2026-06-17T02:14:54.353","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is setuid root. This binary accepts several parameters to update the system configuration. These parameters are passed to operating system commands using a \"here\" document. The parameters are not sanitized, which allow for arbitrary commands to be injected using shell metacharacters. A local unprivileged user can pass special crafted parameters that will be interpolated by the operating system calls."},{"lang":"es","value":"Una vulnerabilidad en el cliente VPN de Private Internet Access (PIA) de London Trust Media para Linux y macOS, podría permitir a un atacante local autenticado ejecutar código arbitrario con privilegios elevados. El binario openvpn_launcher.64 de binarios de PIA para Linux/macOS es root setuid. Este binario acepta varios parámetros para actualizar la configuración del sistema. Estos parámetros se pasan a los comandos del sistema operativo mediante un documento \"here\". Los parámetros no se sanean, lo que permite inyectar comandos arbitrarios utilizando metacaracteres de shell. Un usuario local sin privilegios puede pasar parámetros diseñados especiales que se interpolarán mediante las llamadas del sistema operativo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:londontrustmedia:private_internet_access_vpn_client:82:*:*:*:*:*:*:*","matchCriteriaId":"23845C1B-3AC7-426E-92C5-9EE5CAC42B68"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}],"references":[{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12579.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/mirchr/security-research/blob/master/vulnerabilities/PIA/CVE-2019-12579.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-15590","sourceIdentifier":"cve@mitre.org","published":"2020-09-14T22:15:11.503","lastModified":"2026-06-17T02:56:52.307","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic. Since 1.5, PIA has supported a “split tunnel” OpenVPN bypass option. The PIA killswitch & associated iptables firewall is designed to protect you while using the Internet. When the kill switch is configured to block all inbound and outbound network traffic, privileged applications can continue sending & receiving network traffic if net.ipv4.ip_forward has been enabled in the system kernel parameters. For example, a Docker container running on a host with the VPN turned off, and the kill switch turned on, can continue using the internet, leaking the host IP (CWE 200). In PIA 2.4.0+, policy-based routing is enabled by default and is used to direct all forwarded packets to the VPN interface automatically."},{"lang":"es","value":"Una vulnerabilidad en el Private Internet Access (PIA) VPN Client  para Linux versiones 1.5 hasta 2.3+, permite a atacantes remotos omitir un mecanismo de desconexión automática de VPN previsto y leer información confidencial por medio de la interceptación del tráfico de red.&#xa0;A partir de la versión 1.5, PIA ha admitido una opción de omisión de OpenVPN “split tunnel”.&#xa0;El firewall PIA killswitch &amp; associated iptables asociado está diseñado para protegerle mientras utiliza Internet.&#xa0;Cuando el switch de interrupción está configurado para bloquear todo el tráfico de red entrante y saliente, las aplicaciones privilegiadas pueden continuar enviando y recibiendo tráfico de red si net.ipv4.ip_forward ha sido habilitado en los parámetros del kernel del sistema.&#xa0;Por ejemplo, un contenedor Docker que se ejecuta en un host con la VPN apagada y el switch de interrupción encendido puede continuar usando Internet, filtrando la IP del host (CWE 200).&#xa0;En PIA versiones 2.4.0+, El enrutamiento basado en políticas está habilitado por defecto y es usado para dirigir todos los paquetes reenviados hacia la interfaz VPN automáticamente"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:privateinternetaccess:private_internet_access_vpn_client:*:*:*:*:*:linux:*:*","versionStartIncluding":"1.5.0","versionEndExcluding":"2.4.0","matchCriteriaId":"EF164CA0-C1B5-4D63-808C-F8840290ED6E"}]}]}],"references":[{"url":"https://github.com/sickcodes","source":"cve@mitre.org","tags":["Not Applicable"]},{"url":"https://github.com/sickcodes/security/blob/master/advisories/SICK-2020-001.md","source":"cve@mitre.org","tags":["Exploit","Mitigation","Third Party Advisory"]},{"url":"https://sick.codes/cve-2020-15590/","source":"cve@mitre.org","tags":["Exploit","Mitigation","Third Party Advisory"]},{"url":"https://github.com/sickcodes","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]},{"url":"https://github.com/sickcodes/security/blob/master/advisories/SICK-2020-001.md","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mitigation","Third Party Advisory"]},{"url":"https://sick.codes/cve-2020-15590/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mitigation","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-39241","sourceIdentifier":"security-advisories@github.com","published":"2022-11-02T17:15:17.187","lastModified":"2026-06-17T04:57:58.813","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumeration on the local host or other hosts on the internal network, as well as against hosts on the Internet. Latest `stable`, `beta`, and `test-passed` versions are now patched. As a workaround, self-hosters can use `DISCOURSE_BLOCKED_IP_BLOCKS` env var (which overrides `blocked_ip_blocks` setting) to stop webhooks from accessing private IPs."},{"lang":"es","value":"Discourse es una plataforma para la discusión comunitaria. Un administrador malintencionado podría utilizar esta vulnerabilidad para realizar una enumeración de puertos en el host local u otros hosts de la red interna, así como contra hosts de Internet. Las últimas versiones \"stable\", \"beta\" y `test-passed` ahora están parcheadas. Como workaround, los autohospedadores pueden usar la var de entorno `DISCOURSE_BLOCKED_IP_BLOCKS` (que anula la configuración `blocked_ip_blocks`) para impedir que los webhooks accedan a IP privadas."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"discourse","product":"discourse","versions":[{"version":"<= 2.8.9","status":"affected"},{"version":"<= 2.9.0.beta10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-23T13:55:26.567048Z","id":"CVE-2022-39241","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*","versionEndExcluding":"2.8.10","matchCriteriaId":"6B12D112-6E19-48E4-92C4-0719F6719929"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*","matchCriteriaId":"B3803EF9-A296-42B7-887F-93C5E68E94C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta10:*:*:*:*:*:*","matchCriteriaId":"35BAC488-3622-4B0B-B8EA-879E8C68E8CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*","matchCriteriaId":"8BA3D313-3C11-43E2-A47D-CBB532D1B6F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*","matchCriteriaId":"6F42673E-65F3-4807-9484-20CB747420FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*","matchCriteriaId":"0B91D023-FCE5-4866-AD8B-BBB675763104"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*","matchCriteriaId":"0086484D-0164-449C-8AAE-BE7479CB9706"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*","matchCriteriaId":"F9D1B031-96C7-44C0-A0A0-F67ABE55C93C"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*","matchCriteriaId":"750D2AD9-35E7-4AC7-9C22-AA90DAA34F3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*","matchCriteriaId":"B68E308A-BDAB-4614-A563-4460F7996CBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:discourse:discourse:2.9.0:beta9:*:*:*:*:*:*","matchCriteriaId":"5DEDE4C5-2C2A-4B74-BB41-8AAA0EE636E2"}]}]}],"references":[{"url":"https://github.com/discourse/discourse/security/advisories/GHSA-rcc5-28r3-23rr","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://github.com/discourse/discourse/security/advisories/GHSA-rcc5-28r3-23rr","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-0846","sourceIdentifier":"security@opennms.com","published":"2023-02-22T19:15:11.090","lastModified":"2026-06-17T05:26:26.513","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information. Users\nshould upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and\nHorizon installation instructions state that they are intended for installation\nwithin an organization's private networks and should not be directly accessible\nfrom the Internet."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group ","product":"Horizon","defaultStatus":"unknown","modules":["Alarm detail"],"platforms":["Windows","Linux","MacOS"],"repo":"https://github.com/OpenNMS","versions":[{"version":"26.1.0","lessThan":"31.0.4","versionType":"git","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","modules":["Alarm detail"],"platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS","versions":[{"version":"2020.1.0","lessThan":"2020.1.32","versionType":"git","status":"affected"},{"version":"2021.1.0","lessThan":"2021.1.24","versionType":"git","status":"affected"},{"version":"2022.1.0","lessThan":"2022.1.13","versionType":"git","status":"affected"},{"version":"2023.1.0","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionEndExcluding":"31.0.4","matchCriteriaId":"9DC4EEF4-1204-4051-8E8E-7D3E69911D81"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2023.1.0","matchCriteriaId":"4FCCB664-CCB6-4D87-A2C4-9C216BAC38DB"}]}]}],"references":[{"url":"https://docs.opennms.com/meridian/2022/releasenotes/changelog.html#releasenotes-changelog-Meridian-2022.1.13","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5506/files","source":"security@opennms.com","tags":["Patch"]},{"url":"https://docs.opennms.com/meridian/2022/releasenotes/changelog.html#releasenotes-changelog-Meridian-2022.1.13","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5506/files","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-0815","sourceIdentifier":"security@opennms.com","published":"2023-02-23T15:15:10.897","lastModified":"2026-06-17T05:26:22.290","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users\nshould upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and\nHorizon installation instructions state that they are intended for installation\nwithin an organization's private networks and should not be directly accessible\nfrom the Internet.\n\n\n\n\n\n\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group ","product":"Meridian","defaultStatus":"unaffected","modules":["Jetty","Log4j2"],"platforms":["Windows","Linux","MacOS"],"programFiles":["https://github.com/OpenNMS/opennms/blob/develop/opennms-base-assembly/src/main/filtered/etc/log4j2.xml"],"programRoutines":[{"name":"log4j2.xml"}],"repo":"https://github.com/OpenNMS","versions":[{"version":"2020.1.0","lessThan":"2020.1.32","versionType":"git","status":"affected"},{"version":"2021.1.0","lessThan":"2021.1.24","versionType":"git","status":"affected"},{"version":"2022.1.0","lessThan":"2022.1.13","versionType":"git","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unknown","modules":["Jetty","Log4j2"],"platforms":["Windows","Linux","MacOS"],"programFiles":["https://github.com/OpenNMS/opennms/blob/develop/opennms-base-assembly/src/main/filtered/etc/log4j2.xml"],"programRoutines":[{"name":"log4j2.xml"}],"repo":"https://github.com/OpenNMS","versions":[{"version":"26.0.0","lessThan":"31.0.4","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-11T18:24:22.248673Z","id":"CVE-2023-0815","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionEndExcluding":"31.0.4","matchCriteriaId":"9DC4EEF4-1204-4051-8E8E-7D3E69911D81"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2023.1.0","matchCriteriaId":"4FCCB664-CCB6-4D87-A2C4-9C216BAC38DB"}]}]}],"references":[{"url":"https://docs.opennms.com/meridian/2022/releasenotes/changelog.html#releasenotes-changelog-Meridian-2022.1.13","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5741/files","source":"security@opennms.com","tags":["Patch","Vendor Advisory"]},{"url":"https://docs.opennms.com/meridian/2022/releasenotes/changelog.html#releasenotes-changelog-Meridian-2022.1.13","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5741/files","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-0867","sourceIdentifier":"security@opennms.com","published":"2023-02-23T15:15:11.000","lastModified":"2026-06-17T05:26:31.060","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users\nshould upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and\nHorizon installation instructions state that they are intended for installation\nwithin an organization's private networks and should not be directly accessible\nfrom the Internet.\n\n\n\n\n\n\n\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","modules":["Webapp"],"platforms":["Windows","Linux","MacOS"],"repo":"https://github.com/OpenNMS","versions":[{"version":"2020.1.0","lessThan":"2020.1.32","versionType":"git","status":"affected"},{"version":"2021.1.0","lessThan":"2021.1.24","versionType":"git","status":"affected"},{"version":"2022.1.0","lessThan":"2022.1.13","versionType":"git","status":"affected"},{"version":"2023.1.0","status":"unaffected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"affected","modules":["Webapp"],"platforms":["Windows","Linux","MacOS"],"repo":"https://github.com/OpenNMS","versions":[{"version":"26.0.0","lessThan":"31.0.4","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionEndExcluding":"31.0.4","matchCriteriaId":"9DC4EEF4-1204-4051-8E8E-7D3E69911D81"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2023.1.0","matchCriteriaId":"4FCCB664-CCB6-4D87-A2C4-9C216BAC38DB"}]}]}],"references":[{"url":"https://docs.opennms.com/meridian/2022/releasenotes/changelog.html#releasenotes-changelog-Meridian-2022.1.13","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5765","source":"security@opennms.com","tags":["Patch"]},{"url":"https://docs.opennms.com/meridian/2022/releasenotes/changelog.html#releasenotes-changelog-Meridian-2022.1.13","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5765","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-0868","sourceIdentifier":"security@opennms.com","published":"2023-02-23T15:15:11.090","lastModified":"2026-06-17T05:26:31.180","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users\nshould upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and\nHorizon installation instructions state that they are intended for installation\nwithin an organization's private networks and should not be directly accessible\nfrom the Internet.\n\n\n\n\n\n\n\n\n\n\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unknown","modules":["Graph Results"],"platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS","versions":[{"version":"2022.1.0","lessThan":"2023.1.0","versionType":"git","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unknown","modules":["Graph Results"],"platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS","versions":[{"version":"29.0.0","lessThanOrEqual":"31.0.3","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionEndExcluding":"31.0.4","matchCriteriaId":"9DC4EEF4-1204-4051-8E8E-7D3E69911D81"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2023.1.0","matchCriteriaId":"4FCCB664-CCB6-4D87-A2C4-9C216BAC38DB"}]}]}],"references":[{"url":"https://docs.opennms.com/meridian/2022/releasenotes/changelog.html#releasenotes-changelog-Meridian-2022.1.13","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5740","source":"security@opennms.com","tags":["Patch","Vendor Advisory"]},{"url":"https://docs.opennms.com/meridian/2022/releasenotes/changelog.html#releasenotes-changelog-Meridian-2022.1.13","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5740","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-0869","sourceIdentifier":"security@opennms.com","published":"2023-02-23T15:15:11.190","lastModified":"2026-06-17T05:26:31.300","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4 or newer. \n\n\n\n\n\n\n\n\n\n\n\nMeridian\nand Horizon installation instructions state that they are intended for\ninstallation within an organization's private networks and should not be\ndirectly accessible from the Internet.\n\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group ","product":"Meridian","defaultStatus":"unknown","modules":["webapp"],"platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS","versions":[{"version":"2022.1.0","lessThan":"2023.1.0","versionType":"git","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unknown","modules":["webapp"],"platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS","versions":[{"version":"29.0.0","lessThan":"31.0.4","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionEndExcluding":"31.0.4","matchCriteriaId":"9DC4EEF4-1204-4051-8E8E-7D3E69911D81"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2023.1.0","matchCriteriaId":"4FCCB664-CCB6-4D87-A2C4-9C216BAC38DB"}]}]}],"references":[{"url":"https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.0","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5734","source":"security@opennms.com","tags":["Patch"]},{"url":"https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.0","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5734","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-0870","sourceIdentifier":"security@opennms.com","published":"2023-03-22T19:15:11.817","lastModified":"2026-06-17T05:26:31.423","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to upgrade to Meridian 2023.1.1 or Horizon 31.0.6 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group ","product":"Meridian","defaultStatus":"unknown","modules":["form"],"platforms":["Linux","Windows","MacOS"],"repo":"https://github.com/OpenNMS","versions":[{"version":"2020.1.0","lessThan":"2020.1.33","versionType":"git","status":"affected"},{"version":"2021.1.0 ","lessThan":"2021.1.25","versionType":"git","status":"affected"},{"version":"2022.1.0","lessThan":"2022.1.14","versionType":"git","status":"affected"},{"version":"2023.1.0","lessThan":"2023.1.1","versionType":"git","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"affected","modules":["form"],"platforms":["Windows","Linux","MacOS"],"repo":"https://github.com/OpenNMS","versions":[{"version":"31.0.6","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-25T18:39:58.031528Z","id":"CVE-2023-0870","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionEndExcluding":"31.0.6","matchCriteriaId":"8B1236D1-83CD-4F35-84B3-3D4699276E9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2020.1.0","versionEndExcluding":"2020.1.33","matchCriteriaId":"0F635108-0354-41C2-A2D8-F1297FC9311E"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2021.1.0","versionEndExcluding":"2021.1.25","matchCriteriaId":"AB510EA1-539C-405F-809E-AC6C16FBD6B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2022.1.0","versionEndExcluding":"2022.1.14","matchCriteriaId":"A71A1FDB-72DF-4E73-B4DA-7B475E3730BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:2023.1.0:*:*:*:*:*:*:*","matchCriteriaId":"FD05EE7C-7E63-4AAD-A45F-E1503A1F863B"}]}]}],"references":[{"url":"https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.1","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5835/files","source":"security@opennms.com","tags":["Patch"]},{"url":"https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/5835/files","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-37261","sourceIdentifier":"security-advisories@github.com","published":"2023-07-07T21:15:09.303","lastModified":"2026-06-17T06:07:50.283","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every version of OpenComputers with the Internet Card feature enabled; that is, OpenComputers 1.2.0 until 1.8.3 in their most common, default configurations. If the OpenComputers mod is installed as part of a Minecraft server hosted on a popular cloud hosting provider, such as AWS, GCP and Azure, those metadata services' API endpoints are not forbidden (aka \"blacklisted\") by default. As such, any player can gain access to sensitive information exposed via those metadata servers, potentially allowing them to pivot or privilege escalate into the hosting provider. In addition, IPv6 addresses are not correctly filtered at all, allowing broader access into the local IPv6 network. This can allow a player on a server using an OpenComputers computer to access parts of the private IPv4 address space, as well as the whole IPv6 address space, in order to retrieve sensitive information.\n\nOpenComputers v1.8.3 for Minecraft 1.7.10 and 1.12.2 contains a patch for this issue. Some workarounds are also available. One may disable the Internet Card feature completely. If using OpenComputers 1.3.0 or above, using the allow list (`opencomputers.internet.whitelist` option) will prohibit connections to any IP addresses and/or domains not listed; or one may add entries to the block list (`opencomputers.internet.blacklist` option). More information about mitigations is available in the GitHub Security Advisory."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"MightyPirates","product":"OpenComputers","versions":[{"version":">= 1.2.0, < 1.8.3","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"opencomputers","product":"opencomputers","defaultStatus":"unknown","cpes":["cpe:2.3:a:opencomputers:opencomputers:*:*:*:*:*:minecraft:*:*"],"versions":[{"version":"1.2.0","lessThan":"1.8.3","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-18T18:45:43.083840Z","id":"CVE-2023-37261","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opencomputers:opencomputers:*:*:*:*:*:minecraft:*:*","versionStartIncluding":"1.2.0","versionEndExcluding":"1.8.3","matchCriteriaId":"8DE41EF6-7537-4DE9-AA2D-B91BECF734BE"}]}]}],"references":[{"url":"https://github.com/MightyPirates/OpenComputers/blob/5b2ba76a4c242b369b9b6ac6196fd04d96580ad0/src/main/resources/application.conf#L966-L986","source":"security-advisories@github.com","tags":["Product"]},{"url":"https://github.com/MightyPirates/OpenComputers/blob/5b2ba76a4c242b369b9b6ac6196fd04d96580ad0/src/main/scala/li/cil/oc/Settings.scala#L614-L637","source":"security-advisories@github.com","tags":["Product"]},{"url":"https://github.com/MightyPirates/OpenComputers/commit/d13c015357fd6c42e0a1bdd6e1ef9462f0450a15","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/MightyPirates/OpenComputers/issues/2365","source":"security-advisories@github.com","tags":["Issue Tracking"]},{"url":"https://github.com/MightyPirates/OpenComputers/releases/tag/1.12.2-forge%2F1.8.3","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/MightyPirates/OpenComputers/security/advisories/GHSA-vvfj-xh7c-j2cm","source":"security-advisories@github.com","tags":["Vendor Advisory"]},{"url":"https://github.com/cc-tweaked/CC-Tweaked/security/advisories/GHSA-7p4w-mv69-2wm2","source":"security-advisories@github.com","tags":["Not Applicable"]},{"url":"https://github.com/MightyPirates/OpenComputers/blob/5b2ba76a4c242b369b9b6ac6196fd04d96580ad0/src/main/resources/application.conf#L966-L986","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]},{"url":"https://github.com/MightyPirates/OpenComputers/blob/5b2ba76a4c242b369b9b6ac6196fd04d96580ad0/src/main/scala/li/cil/oc/Settings.scala#L614-L637","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]},{"url":"https://github.com/MightyPirates/OpenComputers/commit/d13c015357fd6c42e0a1bdd6e1ef9462f0450a15","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/MightyPirates/OpenComputers/issues/2365","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"]},{"url":"https://github.com/MightyPirates/OpenComputers/releases/tag/1.12.2-forge%2F1.8.3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/MightyPirates/OpenComputers/security/advisories/GHSA-vvfj-xh7c-j2cm","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://github.com/cc-tweaked/CC-Tweaked/security/advisories/GHSA-7p4w-mv69-2wm2","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]}]}},{"cve":{"id":"CVE-2023-0871","sourceIdentifier":"security@opennms.com","published":"2023-08-11T17:15:08.980","lastModified":"2026-06-17T05:26:31.560","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which can be used for instance to force Horizon to make arbitrary HTTP requests to internal and external services. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Erik Wynter and Moshe Apelbaum for reporting this issue.\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","Linux","MacOS"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"31.0.8","lessThan":"32.0.2","versionType":"maven","status":"affected"},{"version":"0","lessThan":"31.0.8","versionType":"maven","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2023.0.0","lessThan":"2023.1.6","versionType":"maven","status":"affected"},{"version":"2022.0.0","lessThan":"2022.1.19","versionType":"maven","status":"affected"},{"version":"2021.0.0","lessThan":"2021.1.30","versionType":"maven","status":"affected"},{"version":"2020.0.0","lessThan":"2020.1.38","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-01T19:06:46.173797Z","id":"CVE-2023-0871","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-611"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-611"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionStartIncluding":"32.0.0","versionEndExcluding":"32.0.2","matchCriteriaId":"5E348236-BC02-4334-8F84-AC9F91C3D0AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:31.0.8:*:*:*:*:*:*:*","matchCriteriaId":"CB86992A-06FF-4B7D-BFD3-FC04DFC96FBC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2020.0.0","versionEndExcluding":"2020.1.38","matchCriteriaId":"E6B9CB53-0A8C-4DB4-85E8-E0F81D6168AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2021.0.0","versionEndExcluding":"2021.1.30","matchCriteriaId":"BAB4DC97-9047-4302-90A0-4711AE93D364"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2022.1.0","versionEndExcluding":"2022.1.9","matchCriteriaId":"230DB641-455F-4F55-AFB2-1E6D974EE080"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.0.0","versionEndExcluding":"2023.1.6","matchCriteriaId":"9822AB30-2205-496D-952D-A0CFF409B72F"}]}]}],"references":[{"url":"https://docs.opennms.com/horizon/32/releasenotes/changelog.html","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6355","source":"security@opennms.com","tags":["Patch"]},{"url":"https://docs.opennms.com/horizon/32/releasenotes/changelog.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6355","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-0872","sourceIdentifier":"security@opennms.com","published":"2023-08-14T18:15:10.730","lastModified":"2026-06-17T05:26:31.710","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.\n\nOpenNMS thanks Erik Wynter for reporting this issue."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"31.0.8","lessThan":"32.0.2","versionType":"maven","status":"affected"},{"version":"0","lessThan":"31.0.8","versionType":"maven","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2020.0.0","lessThanOrEqual":"2020.1.37","versionType":"maven","status":"affected"},{"version":"2021.0.0","lessThanOrEqual":"2021.1.29","versionType":"maven","status":"affected"},{"version":"2022.0.0","lessThanOrEqual":"2022.1.18","versionType":"maven","status":"affected"},{"version":"2023.0.0","lessThanOrEqual":"2023.1.5","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":5.3},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-03T20:25:17.539547Z","id":"CVE-2023-0872","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionStartIncluding":"31.0.8","versionEndExcluding":"32.0.2","matchCriteriaId":"62C4B0BB-21CA-40FC-8A39-26B86AA35FD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2020.0.0","versionEndIncluding":"2020.1.37","matchCriteriaId":"8437D5CA-17AA-4711-8E3D-DFB237B617AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2021.0.0","versionEndIncluding":"2021.1.29","matchCriteriaId":"19DD5F20-8B2D-4559-AB47-DB4E3CC13DD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2022.0.0","versionEndIncluding":"2022.1.18","matchCriteriaId":"B33DB38B-B66B-4C3F-B4BE-BA2407E99DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.0.0","versionEndIncluding":"2023.1.5","matchCriteriaId":"518ACF5B-D2BB-4014-85C5-6F741041370C"}]}]}],"references":[{"url":"https://docs.opennms.com/horizon/32/releasenotes/changelog.html","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6354","source":"security@opennms.com","tags":["Patch"]},{"url":"https://docs.opennms.com/horizon/32/releasenotes/changelog.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6354","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-40311","sourceIdentifier":"security@opennms.com","published":"2023-08-14T18:15:11.247","lastModified":"2026-06-17T06:17:12.550","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple stored XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that allow an attacker to store on database and then load on JSPs or Angular templates. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Jordi Miralles Comins for reporting this issue.\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"31.0.8","lessThan":"32.0.2","versionType":"maven","status":"affected"},{"version":"0","lessThan":"31.0.8","versionType":"maven","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","Linux","MacOS"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2020.0.0","lessThanOrEqual":"2020.1.37","versionType":"maven","status":"affected"},{"version":"2021.0.0","lessThanOrEqual":"2021.1.29","versionType":"maven","status":"affected"},{"version":"2022.0.0","lessThanOrEqual":"2022.1.18","versionType":"maven","status":"affected"},{"version":"2023.0.0","lessThanOrEqual":"2023.1.5","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-27T21:49:38.301995Z","id":"CVE-2023-40311","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionStartIncluding":"31.0.8","versionEndExcluding":"32.0.2","matchCriteriaId":"62C4B0BB-21CA-40FC-8A39-26B86AA35FD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2020.1.38","matchCriteriaId":"B2D5D1D2-CF1D-4F19-AEAF-FFCFC79776FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2022.1.0","versionEndExcluding":"2022.1.19","matchCriteriaId":"036E7C54-677A-4656-89E0-CC0134F51642"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.1.0","versionEndExcluding":"2023.1.6","matchCriteriaId":"CA718877-9AB1-43FF-B1E5-9A47992EC1EC"}]}]}],"references":[{"url":"https://github.com/OpenNMS/opennms","source":"security@opennms.com","tags":["Product"]},{"url":"https://github.com/OpenNMS/opennms/pull/6365","source":"security@opennms.com","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/OpenNMS/opennms/pull/6366","source":"security@opennms.com","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/OpenNMS/opennms","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]},{"url":"https://github.com/OpenNMS/opennms/pull/6365","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/OpenNMS/opennms/pull/6366","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-40312","sourceIdentifier":"security@opennms.com","published":"2023-08-14T18:15:11.420","lastModified":"2026-06-17T06:17:12.913","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple reflected XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that an attacker can modify to craft a malicious XSS payload. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Jordi Miralles Comins for reporting this issue.\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"31.0.8","lessThan":"32.0.2","versionType":"maven","status":"affected"},{"version":"0","lessThan":"31.0.8","versionType":"maven","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2020.0.0","lessThanOrEqual":"2020.1.37","versionType":"maven","status":"affected"},{"version":"2021.0.0","lessThanOrEqual":"2021.1.29","versionType":"maven","status":"affected"},{"version":"2022.0.0","lessThanOrEqual":"2022.1.18","versionType":"maven","status":"affected"},{"version":"2023.0.0","lessThanOrEqual":"2023.1.5","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":5.2,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-27T21:49:35.769106Z","id":"CVE-2023-40312","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionStartIncluding":"31.0.8","versionEndExcluding":"32.0.2","matchCriteriaId":"62C4B0BB-21CA-40FC-8A39-26B86AA35FD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2020.1.38","matchCriteriaId":"B2D5D1D2-CF1D-4F19-AEAF-FFCFC79776FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2022.1.0","versionEndExcluding":"2022.1.19","matchCriteriaId":"036E7C54-677A-4656-89E0-CC0134F51642"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.1.0","versionEndExcluding":"2023.1.6","matchCriteriaId":"CA718877-9AB1-43FF-B1E5-9A47992EC1EC"}]}]}],"references":[{"url":"https://docs.opennms.com/horizon/32/releasenotes/changelog.html","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6356","source":"security@opennms.com","tags":["Patch","Vendor Advisory"]},{"url":"https://docs.opennms.com/horizon/32/releasenotes/changelog.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6356","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-40313","sourceIdentifier":"security@opennms.com","published":"2023-08-17T19:15:13.220","lastModified":"2026-06-17T06:17:13.293","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code execution. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet."},{"lang":"es","value":"Un intérprete de BeanShell en modo servidor remoto se ejecuta en versiones de OpenNMS Horizon anteriores a 32.0.2 y en versiones de Meridian relacionadas, lo que podría permitir la ejecución remota arbitraria de código Java. La solución es actualizar a Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 u Horizon 32.0.2 o posterior. Las instrucciones de instalación de Meridian y Horizon indican que están pensadas para instalarse dentro de las redes privadas de una organización y que no debe accederse a ellas directamente desde Internet."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"29.0.4","lessThan":"32.0.2","versionType":"maven","status":"affected"},{"version":"0","lessThan":"29.0.4","versionType":"maven","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2020.0.0","lessThanOrEqual":"2020.1.37","versionType":"maven","status":"affected"},{"version":"2021.0.0","lessThanOrEqual":"2021.1.29","versionType":"maven","status":"affected"},{"version":"2022.0.0","lessThanOrEqual":"2022.1.18","versionType":"maven","status":"affected"},{"version":"2023.0.0","lessThanOrEqual":"2023.1.5","versionType":"maven","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"opennms","product":"horizon","defaultStatus":"unknown","cpes":["cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*"],"versions":[{"version":"29.0.4","lessThan":"32.0.2","versionType":"maven","status":"affected"},{"version":"0","lessThan":"29.0.4","versionType":"maven","status":"unknown"}]},{"vendor":"opennms","product":"meridian","defaultStatus":"unknown","cpes":["cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*"],"versions":[{"version":"2020.0.0","lessThanOrEqual":"2020.1.37","versionType":"maven","status":"affected"},{"version":"2021.0.0","lessThanOrEqual":"2021.1.29","versionType":"maven","status":"affected"},{"version":"2022.0.0","lessThanOrEqual":"2022.1.18","versionType":"maven","status":"affected"},{"version":"2023.0.0","lessThanOrEqual":"2023.1.5","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-08T12:59:42.694660Z","id":"CVE-2023-40313","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionEndExcluding":"32.0.2","matchCriteriaId":"B1F43487-53A1-4CB8-8771-46E4F904D3AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2020.1.38","matchCriteriaId":"B2D5D1D2-CF1D-4F19-AEAF-FFCFC79776FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2021.1.0","versionEndExcluding":"2021.1.30","matchCriteriaId":"996A419A-2DC1-4F83-B0D7-EE97031F8A59"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2022.1.0","versionEndExcluding":"2022.1.19","matchCriteriaId":"036E7C54-677A-4656-89E0-CC0134F51642"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.1.0","versionEndExcluding":"2023.1.6","matchCriteriaId":"CA718877-9AB1-43FF-B1E5-9A47992EC1EC"}]}]}],"references":[{"url":"https://docs.opennms.com/horizon/32/releasenotes/changelog.html","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6368","source":"security@opennms.com","tags":["Issue Tracking","Patch"]},{"url":"https://docs.opennms.com/horizon/32/releasenotes/changelog.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6368","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"]}]}},{"cve":{"id":"CVE-2023-40315","sourceIdentifier":"security@opennms.com","published":"2023-08-17T20:15:11.287","lastModified":"2026-06-17T06:17:14.110","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily escalate their privileges to ROLE_ADMIN or any other role. The solution is to upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Erik Wynter for reporting this issue."},{"lang":"es","value":"En OpenNMS Horizon 31.0.8 y versiones anteriores a 32.0.2 y versiones Meridian relacionadas, cualquier usuario que tenga el ROLE_FILESYSTEM_EDITOR puede escalar fácilmente sus privilegios a ROLE_ADMIN o cualquier otro rol. La solución es actualizar a Meridian 2023.1.5 u Horizon 32.0.2 o posterior. Las instrucciones de instalación de Meridian y Horizon indican que están pensadas para su instalación dentro de las redes privadas de una organización y que no se debe acceder a ellas directamente desde Internet. OpenNMS da las gracias a Erik Wynter por informar de este problema.\n"}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"31.0.8","lessThan":"32.0.2","versionType":"maven","status":"affected"},{"version":"0","lessThan":"31.0.8","versionType":"maven","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2023.0.0","lessThan":"2023.1.5","versionType":"maven","status":"affected"},{"version":"0","lessThan":"2023.0.0","versionType":"maven","status":"unknown"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":0.5,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-01T17:47:10.985903Z","id":"CVE-2023-40315","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionStartIncluding":"31.0.8","versionEndExcluding":"32.0.2","matchCriteriaId":"62C4B0BB-21CA-40FC-8A39-26B86AA35FD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.0.0","versionEndExcluding":"2023.1.5","matchCriteriaId":"4F1924FB-1A45-49FE-9C2E-A834AE9F4C03"}]}]}],"references":[{"url":"https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.5","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6250","source":"security@opennms.com","tags":["Patch"]},{"url":"https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.5","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6250","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-40612","sourceIdentifier":"security@opennms.com","published":"2023-08-23T19:15:08.443","lastModified":"2026-06-17T06:18:43.630","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection attacks. The solution is to upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Erik Wynter for reporting this issue."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"31.0.8","lessThan":"32.0.2","versionType":"maven","status":"affected"},{"version":"0","lessThan":"31.0.8","versionType":"maven","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2023.0.0","lessThan":"2023.1.5","versionType":"maven","status":"affected"},{"version":"0","lessThan":"2023.0.0","versionType":"maven","status":"unknown"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":0.5,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-01T15:11:10.621070Z","id":"CVE-2023-40612","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-91"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-91"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionStartIncluding":"31.0.8","versionEndExcluding":"32.0.2","matchCriteriaId":"62C4B0BB-21CA-40FC-8A39-26B86AA35FD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.0.0","versionEndExcluding":"2023.1.5","matchCriteriaId":"4F1924FB-1A45-49FE-9C2E-A834AE9F4C03"}]}]}],"references":[{"url":"https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.5","source":"security@opennms.com","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6288","source":"security@opennms.com","tags":["Patch"]},{"url":"https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.5","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenNMS/opennms/pull/6288","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-40314","sourceIdentifier":"security@opennms.com","published":"2023-11-16T22:15:27.947","lastModified":"2026-06-17T06:17:13.760","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"\n\n\nCross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Horizon 32.0.5 or newer and Meridian 2023.1.9 or newer\n\n\n\n\n\n\n\n\n\n\nMeridian\nand Horizon installation instructions state that they are intended for\ninstallation within an organization's private networks and should not be\ndirectly accessible from the Internet. \n\nOpenNMS thanks \n\nMoshe Apelbaum\n\n for reporting this issue.\n\n\n\n\n\n\n\n"},{"lang":"es","value":"Cross-Site Scripting (XSS) en bootstrap.jsp en múltiples versiones de OpenNMS Meridian y Horizon permiten que un atacante acceda a información confidencial de la sesión. La solución es actualizar a Horizon 32.0.5 o posterior y Meridian 2023.1.9 o posterior. Las instrucciones de instalación de Meridian y Horizon indican que están diseñadas para su instalación dentro de las redes privadas de una organización y no se debe acceder a ellas directamente desde Internet. OpenNMS agradece a Moshe Apelbaum por informar este problema."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":" The OpenNMS Group","product":"Horizon","defaultStatus":"unknown","modules":["webapp"],"platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS","versions":[{"version":"31.0.8","lessThan":"32.0.4","versionType":"git","status":"affected"}]},{"vendor":"The OpenNMS Group ","product":"Meridian","defaultStatus":"unaffected","modules":["webapp"],"platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS","versions":[{"version":"0","lessThan":"2023.1.8","versionType":"git","status":"unknown"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-29T14:44:57.380992Z","id":"CVE-2023-40314","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*","versionEndExcluding":"32.0.5","matchCriteriaId":"94B45FA1-ADAF-421C-A461-DEF18A5C2456"},{"vulnerable":true,"criteria":"cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*","versionEndExcluding":"2023.1.9","matchCriteriaId":"1F8F6EBD-EE5B-4F43-BE5C-674A138FF6AE"}]}]}],"references":[{"url":"https://github.com/OpenNMS/opennms/pull/6791","source":"security@opennms.com","tags":["Patch"]},{"url":"https://github.com/OpenNMS/opennms/pull/6791","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2025-24888","sourceIdentifier":"security-advisories@github.com","published":"2025-02-13T18:18:23.047","lastModified":"2026-06-17T08:59:47.383","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to version 0.14.1, a malicious SecureDrop Server could obtain code execution on the SecureDrop Client virtual machine (`sd-app`). SecureDrop Server itself has multiple layers of built-in hardening, and is a dedicated physical machine exposed on the internet only via Tor hidden services for the Source and Journalist interfaces, and optionally via remote SSH access over another Tor hidden service. A newsroom's SecureDrop Workstation communicates only with its own dedicated SecureDrop Server.\n\nThe SecureDrop Client runs in a dedicated Qubes virtual machine, named `sd-app`, as part of the SecureDrop Workstation. The private OpenPGP key used to decrypt submissions and replies is stored in a separate virtual machine and never accessed directly. The vulnerability lies in the code responsible for downloading replies. The filename of the reply is obtained from the `Content-Disposition` HTTP header and used to write the encrypted reply on disk. Note that filenames are generated and sanitized server-side, and files are downloaded in an encrypted format, so a remote attacker who has not achieved server compromise, such as one posing as a source, could not craft the HTTP response necessary for this attack.\n\nWhile the filename is later checked to guard against path traversal before being moved into the Client’s data storage directory, the file has already been written to a potentially arbitrary location. In this case, `safe_move()` would detect the path traversal and fail, leaving the original downloaded file in the attacker-chosen directory. Code execution can be gained by writing an autostart file in `/home/user/.config/autostart/`.\n\nVersion 0.14.1 fixes the issue. As of time of publication, there is no known evidence of exploitation in the wild. This attack requires a previously compromised SecureDrop Server."},{"lang":"es","value":"SecureDrop Client es una aplicación de escritorio para que los periodistas se comuniquen con las fuentes y trabajen con los envíos en la Estación de trabajo SecureDrop. Antes de la versión 0.14.1, un Servidor SecureDrop malicioso podía obtener la ejecución de código en la máquina virtual del Cliente SecureDrop (`sd-app`). El Servidor SecureDrop en sí tiene múltiples capas de protección integradas y es una máquina física dedicada expuesta en Internet solo a través de servicios ocultos de Tor para las interfaces de Fuente y Periodista, y opcionalmente a través de acceso SSH remoto a través de otro servicio oculto de Tor. La Estación de trabajo SecureDrop de una sala de redacción se comunica solo con su propio Servidor SecureDrop dedicado. El Cliente SecureDrop se ejecuta en una máquina virtual Qubes dedicada, llamada `sd-app`, como parte de la Estación de trabajo SecureDrop. La clave privada OpenPGP utilizada para descifrar los envíos y las respuestas se almacena en una máquina virtual separada y nunca se accede a ella directamente. La vulnerabilidad reside en el código responsable de descargar las respuestas. El nombre de archivo de la respuesta se obtiene del encabezado HTTP `Content-Disposition` y se utiliza para escribir la respuesta cifrada en el disco. Tenga en cuenta que los nombres de archivo se generan y se depuran en el servidor, y los archivos se descargan en un formato cifrado, por lo que un atacante remoto que no haya logrado comprometer el servidor, como uno que se haga pasar por una fuente, no podría manipular la respuesta HTTP necesaria para este ataque. Si bien el nombre de archivo se verifica más tarde para protegerse contra el path traversal antes de moverlo al directorio de almacenamiento de datos del cliente, el archivo ya se ha escrito en una ubicación potencialmente arbitraria. En este caso, `safe_move()` detectaría el path traversal y fallaría, dejando el archivo descargado original en el directorio elegido por el atacante. La ejecución del código se puede obtener escribiendo un archivo de inicio automático en `/home/user/.config/autostart/`. La versión 0.14.1 corrige el problema. Al momento de la publicación, no hay evidencia conocida de explotación en la naturaleza. Este ataque requiere un servidor SecureDrop previamente comprometido."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"freedomofpress","product":"securedrop-client","versions":[{"version":"< 0.14.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-13T19:08:23.148435Z","id":"CVE-2025-24888","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/freedomofpress/securedrop-client/blob/0.14.0/client/securedrop_client/utils.py#L79","source":"security-advisories@github.com"},{"url":"https://github.com/freedomofpress/securedrop-client/blob/main/client/securedrop_client/api_jobs/downloads.py#L164","source":"security-advisories@github.com"},{"url":"https://github.com/freedomofpress/securedrop-client/blob/release/0.14.0/client/securedrop_client/sdk/__init__.py#L956-L957","source":"security-advisories@github.com"},{"url":"https://github.com/freedomofpress/securedrop-client/commit/120bac14649db0bcf5f24f2eb82731c76843b1ba","source":"security-advisories@github.com"},{"url":"https://github.com/freedomofpress/securedrop-client/security/advisories/GHSA-6c3p-chq6-q3j2","source":"security-advisories@github.com"},{"url":"https://www.qubes-os.org/doc/split-gpg","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2025-53121","sourceIdentifier":"security@opennms.com","published":"2025-06-26T19:15:21.960","lastModified":"2026-06-17T09:37:39.390","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple stored XSS were found on different nodes with unsanitized parameters in OpenMNS Horizon 33.0.8 and versions earlier than 33.1.6 on multiple platforms that allow an attacker to store on database and then inject HTML and/or Javascript on the page. The solution is to upgrade to Horizon 33.1.6, 33.1.7 or Meridian 2024.2.6, 2024.2.7 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Fábio Tomé for reporting this issue."},{"lang":"es","value":"Se encontraron múltiples XSS almacenado en diferentes nodos con parámetros no saneados en OpenMNS Horizon 33.0.8 y versiones anteriores a la 33.1.6 en varias plataformas, lo que permite a un atacante almacenarlos en una base de datos e inyectar HTML o Javascript en la página. La solución es actualizar a Horizon 33.1.6, 33.1.7 o Meridian 2024.2.6, 2024.2.7 o posterior. Las instrucciones de instalación de Meridian y Horizon indican que están diseñados para instalarse en las redes privadas de una organización y no deben ser accesibles directamente desde Internet. OpenNMS agradece a Fábio Tomé por informar sobre este problema."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"33.0.8","lessThan":"33.1.6, 33.1.7","versionType":"maven","status":"affected"},{"version":"0","lessThan":"33.0.8","versionType":"maven","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2024.1.4","lessThan":"2024.2.6, 2024.2.7","versionType":"maven","status":"affected"},{"version":"2023.1.20","lessThan":"2024.2.6, 2024.2.7","versionType":"maven","status":"affected"},{"version":"2023.0.0","lessThanOrEqual":"2023.1.20","versionType":"maven","status":"unknown"},{"version":"2024.0.0","lessThanOrEqual":"2024.1.4","versionType":"maven","status":"unknown"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-26T19:07:17.741126Z","id":"CVE-2025-53121","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/OpenNMS/opennms","source":"security@opennms.com"},{"url":"https://github.com/OpenNMS/opennms/pull/7708","source":"security@opennms.com"}]}},{"cve":{"id":"CVE-2025-53122","sourceIdentifier":"security@opennms.com","published":"2025-06-26T20:15:32.063","lastModified":"2026-06-17T09:37:39.513","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection. \n\nUsers\nshould upgrade to Meridian 2024.2.6 or newer, or Horizon 33.16 or newer. Meridian and\nHorizon installation instructions state that they are intended for installation\nwithin an organization's private networks and should not be directly accessible\nfrom the Internet."},{"lang":"es","value":"La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en las aplicaciones OpenNMS Horizon y Meridian permite la inyección SQL. Los usuarios deben actualizar a Meridian 2024.2.6 o posterior, o a Horizon 33.16 o posterior. Las instrucciones de instalación de Meridian y Horizon indican que están diseñadas para instalarse en las redes privadas de una organización y no deben ser accesibles directamente desde Internet."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"25.2.1","lessThan":"33.1.6, 33.1.7","versionType":"git","status":"affected"},{"version":"33.0.8","lessThan":"33.1.6, 33.1.7","versionType":"git","status":"affected"},{"version":"25.2.1","lessThanOrEqual":"33.0.8","versionType":"git","status":"unknown"}]},{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"repo":"https://github.com/OpenNMS/opennms","versions":[{"version":"2024.1.0","lessThan":"2024.2.6, 2024.2.7","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-26T20:03:35.437698Z","id":"CVE-2025-53122","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://docs.opennms.com/meridian/2024/releasenotes/changelog.html#releasenotes-changelog-Meridian-2024.2.6","source":"security@opennms.com"},{"url":"https://github.com/OpenNMS/opennms/pull/7709","source":"security@opennms.com"}]}},{"cve":{"id":"CVE-2022-50924","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-01-13T23:15:56.503","lastModified":"2026-06-17T05:24:25.930","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup."},{"lang":"es","value":"Private Internet Access 3.3 contiene una vulnerabilidad de ruta de servicio sin comillas que permite a usuarios locales ejecutar potencialmente código arbitrario con privilegios de sistema elevados. Los atacantes pueden explotar la ruta sin comillas en la configuración del servicio para inyectar código malicioso que se ejecutaría con permisos de LocalSystem durante el inicio del servicio."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Private Internet Access","product":"Private Internet Access","versions":[{"version":"3.3.0.100","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-14T15:50:38.241877Z","id":"CVE-2022-50924","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-428"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/50804","source":"disclosure@vulncheck.com"},{"url":"https://www.privateinternetaccess.com","source":"disclosure@vulncheck.com"},{"url":"https://www.privateinternetaccess.com/download","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/private-internet-access-pia-service-unquoted-service-path","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-33619","sourceIdentifier":"security-advisories@github.com","published":"2026-03-26T21:17:06.220","lastModified":"2026-06-17T10:37:47.740","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains a server-side request forgery issue in the optional scheduler's webhook delivery path. When a task is submitted to `POST /tasks` with a user-controlled `callbackUrl`, the v0.8.3 scheduler sends an outbound HTTP `POST` to that URL when the task reaches a terminal state. In that release, the webhook path validated only the URL scheme and did not reject loopback, private, link-local, or other non-public destinations. Because the v0.8.3 implementation also used the default HTTP client behavior, redirects were followed and the destination was not pinned to validated IPs. This allowed blind SSRF from the PinchTab server to attacker-chosen HTTP(S) targets reachable from the server. This issue is narrower than a general unauthenticated internet-facing SSRF. The scheduler is optional and off by default, and in token-protected deployments the attacker must already be able to submit tasks using the server's master API token. In PinchTab's intended deployment model, that token represents administrative control rather than a low-privilege role. Tokenless deployments lower the barrier further, but that is a separate insecure configuration state rather than impact created by the webhook bug itself. PinchTab's default deployment model is local-first and user-controlled, with loopback bind and token-based access in the recommended setup. That lowers practical risk in default use, even though it does not remove the underlying webhook issue when the scheduler is enabled and reachable. This was addressed in v0.8.4 by validating callback targets before dispatch, rejecting non-public IP ranges, pinning delivery to validated IPs, disabling redirect following, and validating `callbackUrl` during task submission."},{"lang":"es","value":"PinchTab es un servidor HTTP autónomo que otorga a los agentes de IA control directo sobre un navegador Chrome. PinchTab v0.8.3 contiene un problema de falsificación de petición del lado del servidor en la ruta de entrega de webhook del programador opcional. Cuando se envía una tarea a 'POST /tasks' con una 'callbackUrl' controlada por el usuario, el programador v0.8.3 envía un 'POST' HTTP saliente a esa URL cuando la tarea alcanza un estado terminal. En esa versión, la ruta del webhook validaba solo el esquema de la URL y no rechazaba destinos de bucle invertido, privados, de enlace local u otros no públicos. Debido a que la implementación v0.8.3 también utilizaba el comportamiento predeterminado del cliente HTTP, se seguían las redirecciones y el destino no estaba fijado a IPs validadas. Esto permitía SSRF ciego desde el servidor PinchTab a objetivos HTTP(S) elegidos por el atacante accesibles desde el servidor. Este problema es más limitado que un SSRF general no autenticado y expuesto a internet. El programador es opcional y está desactivado por defecto, y en implementaciones protegidas por token el atacante ya debe ser capaz de enviar tareas utilizando el token maestro de la API del servidor. En el modelo de implementación previsto de PinchTab, ese token representa control administrativo en lugar de un rol de bajo privilegio. Las implementaciones sin token reducen aún más la barrera, pero eso es un estado de configuración inseguro separado en lugar del impacto creado por el propio error del webhook. El modelo de implementación predeterminado de PinchTab es local-first y controlado por el usuario, con enlace de bucle invertido y acceso basado en token en la configuración recomendada. Eso reduce el riesgo práctico en el uso predeterminado, aunque no elimina el problema subyacente del webhook cuando el programador está habilitado y es accesible. Esto se abordó en la v0.8.4 validando los objetivos de callback antes del envío, rechazando rangos de IP no públicos, fijando la entrega a IPs validadas, deshabilitando el seguimiento de redirecciones y validando 'callbackUrl' durante el envío de tareas."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pinchtab","product":"pinchtab","versions":[{"version":"< 0.8.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-30T11:34:33.142945Z","id":"CVE-2026-33619","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pinchtab:pinchtab:*:*:*:*:*:*:*:*","versionEndExcluding":"0.8.4","matchCriteriaId":"8BA92C50-3F9B-49D5-B05E-5CE50B3CA46C"}]}]}],"references":[{"url":"https://github.com/pinchtab/pinchtab/commit/c824574c3a05073dec2f5e9c219e22ffff8de445","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/pinchtab/pinchtab/releases/tag/v0.8.4","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/pinchtab/pinchtab/security/advisories/GHSA-xqq2-4j46-vwp7","source":"security-advisories@github.com","tags":["Exploit","Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-19135","sourceIdentifier":"security@opennms.com","published":"2026-08-13T05:17:22.750","lastModified":"2026-09-08T19:20:25.117","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attacker to gain access to confidential information and compromise integrity.\n\nThe solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"2024.1.0","lessThan":"2024.3.12","versionType":"maven","status":"affected"},{"version":"2025.0.0","lessThan":"2025.0.9","versionType":"maven","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"36.0.0","lessThan":"36.0.3","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T13:02:12.787202Z","id":"CVE-2026-19135","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-470"}]}],"references":[{"url":"https://github.com/OpenNMS/opennms/pull/8754","source":"security@opennms.com"}]}},{"cve":{"id":"CVE-2026-19182","sourceIdentifier":"security@opennms.com","published":"2026-08-13T05:17:22.893","lastModified":"2026-09-08T19:20:25.117","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction. A credential check that should restrict these operations is guarded by an inverted condition, so it never executes for a real (non-blank) username. This can potentially allow an attacker to compromise the integrity of alarm state and audit records.\n\n\n\nThe solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"2024.1.0","lessThan":"2024.3.12","versionType":"maven","status":"affected"},{"version":"2025.0.0","lessThan":"2025.0.9","versionType":"maven","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"36.0.0","lessThan":"36.0.3","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T13:01:50.881107Z","id":"CVE-2026-19182","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/OpenNMS/opennms/pull/8755","source":"security@opennms.com"}]}},{"cve":{"id":"CVE-2026-89054","sourceIdentifier":"security@opennms.com","published":"2026-09-10T20:17:31.973","lastModified":"2026-09-18T19:21:34.307","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are reachable with no authorization enforced. An unauthenticated attacker able to reach the web UI can disable event definitions and SNMP data collection, suppressing event and alarm generation and stopping metric collection - silently degrading monitoring and detection - with the change persisted and reloaded into the running system.\n\n\n\nThe solution is to upgrade to Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"36.0.0","lessThan":"36.0.4","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-10T20:02:50.943401Z","id":"CVE-2026-89054","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/OpenNMS/opennms/pull/8833","source":"security@opennms.com"}]}},{"cve":{"id":"CVE-2026-19596","sourceIdentifier":"security@opennms.com","published":"2026-09-10T21:17:25.667","lastModified":"2026-09-18T19:21:34.307","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon. When OpenNMS collects XML from a source whose response is attacker-controlled (for example a compromised monitored host or an HTTP man-in-the-middle position), the collector's XML parser resolves external entities and external DTDs. This allows an attacker to read files accessible to the OpenNMS service account, including database credentials, and to induce out-of-band requests.\n\n\n\nThe solution is to upgrade to Meridian 2024.3.13, 2025.0.10 and Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"2024.1.0","lessThan":"2024.3.13","versionType":"maven","status":"affected"},{"version":"2025.0.0","lessThan":"2025.0.10","versionType":"maven","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"36.0.0","lessThan":"36.0.4","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-10T20:27:39.274555Z","id":"CVE-2026-19596","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-611"}]}],"references":[{"url":"https://github.com/OpenNMS/opennms/pull/8782","source":"security@opennms.com"}]}},{"cve":{"id":"CVE-2026-89089","sourceIdentifier":"security@opennms.com","published":"2026-09-10T21:17:53.033","lastModified":"2026-09-18T19:21:34.307","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports \"Maintenance contracts expired\" (AssetManagementMaintExpired) and \"Maintenance contracts strategy\" (AssetManagementMaintStrategy) via the reporting REST API (POST /rest/reports/{id}) and supply a DATE_FORMAT parameter that the report templates substitute literally, un-escaped, into their SQL queries. This lets an attacker execute arbitrary SQL against the OpenNMS database and read arbitrary data, including database-stored secrets such as provisioning and notification credentials and SNMP community strings.\n\n\n\nThe solution is to upgrade to Meridian 2024.3.13, 2025.0.10 and Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet."}],"affected":[{"source":"security@opennms.com","affectedData":[{"vendor":"The OpenNMS Group","product":"Meridian","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"2024.1.0","lessThan":"2024.3.13","versionType":"maven","status":"affected"},{"version":"2025.0.0","lessThan":"2025.0.10","versionType":"maven","status":"affected"}]},{"vendor":"The OpenNMS Group","product":"Horizon","defaultStatus":"unaffected","repo":"https://github.com/OpenNMS","versions":[{"version":"36.0.0","lessThan":"36.0.4","versionType":"maven","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@opennms.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-11T14:51:29.896443Z","id":"CVE-2026-89089","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@opennms.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/OpenNMS/opennms/pull/8832","source":"security@opennms.com"}]}}]}