The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improper Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade github.com/l3montree-dev/devguard/middlewares to version 1.4.2 or higher.
Affected versions of this package are vulnerable to Improper Authorization in the authorization process for public assets. An attacker can perform unauthorized actions such as creating, updating, reapplying, and deleting VEX rules, as well as making changes to vulnerability-triage endpoints, dependency-vuln events, batch events, vulnerability synchronization, mitigation, license risk creation, external reference writes, and artifact creation by using a valid account on the instance, even without membership in the victim organization, project, or asset. This is only exploitable if the targeted asset is configured as public.
This vulnerability can be mitigated by changing the asset visibility from public to private in the asset settings, which restores correct authorization on all write endpoints for that asset.