The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade thumbor to version 7.8.0 or higher.
thumbor is a thumbor is an open-source photo thumbnail service by globo.com
Affected versions of this package are vulnerable to Division by zero via the convolution filter process in the C extension when user-controlled input is used as a divisor without validation. An attacker can cause the process to crash and disrupt service by supplying a crafted value that triggers a divide-by-zero error. This is only exploitable if the convolution filter is enabled (enabled by default), and either /unsafe/ URLs are allowed or the attacker has access to a valid signed URL.