VendorsLF Projectsminderany version
Vulnerabilities

LF Projects Minder any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-27093
Minder trusts client-provided mapping from repo name to upstream ID
Published 2024-02-26 · Analyzed
7.5EPSS 0.006
CVE-2024-27916
`GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any authenticated user
Published 2024-03-06 · Analyzed
7.1EPSS 0.007