The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/rclone/rclone/cmd/server to version 1.75.1 or higher.
Affected versions of this package are vulnerable to External Control of File Name or Path through the newVolume process in the Docker volume plugin when the name field of a VolumeDriver.Create request is not properly validated. An attacker can cause the creation and mounting of a remote filesystem at an arbitrary host path, potentially shadowing or disrupting system directories, by submitting a crafted volume name containing directory traversal sequences (such as ..). This is only exploitable if an attacker can submit a VolumeDriver.Create request to the plugin socket, which is typically accessible to the Docker daemon or workloads in a multi-tenant orchestration environment.