VendorsSynopsyscoverityall versions
Vulnerabilities

Synopsys Coverity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-23849
Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same sub domain can set a cookie for the whole subdomain which can be used to bypass other mitigations in place for malicious purposes. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/RL:O/RC:C
Published 2023-02-06 · Modified
8.1EPSS 0.013
CVE-2023-1663
Authenticated Resources Accessible via Forced Browsing
Published 2023-03-29 · Modified
6.5EPSS 0.004