The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsA fix was pushed into the master branch but not yet published.
Affected versions of this package are vulnerable to Arbitrary Code Injection through the createPlugin and updatePlugin handlers. An attacker can load arbitrary native code into the gateway process by sending POST /api/plugins or PUT /api/plugins/{name} with a non-builtin path when dashboard authentication is disabled or unconfigured. Because the plugin path is treated as a shared object and dlopen()'d in-process, a successful request lets the attacker execute code as the Bifrost process user. For affected deployments that leave management authentication off, this turns a reachable admin endpoint into remote code execution and can compromise the gateway host.
Workarounds
path through /api/plugins or /api/plugins/{name}; this prevents unauthenticated callers from setting a plugin path that would be loaded as native code in the gateway process..so files on an internal/private-network URL, add that host to server.plugin_download_private_allowlist; this prevents the plugin downloader from blocking your trusted artifact source while still limiting exposure to SSRF against internal or metadata endpoints.