Skip to main content

Threats Tagged 'cwe-441'

View all threats tagged with 'cwe-441'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-441

Threats Tagged 'cwe-441'

Click on any threat for detailed analysis and mitigation recommendations

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

Join the discussion

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the response as a document at the application's own origin, allowing script in that response to access same-origin storage, cookies, and registered Capacitor plugin capabilities. Applications remain affected when CapacitorHttp is disabled because affected releases serve the proxy path regardless of that setting. This issue is fixed in versions 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1.

Join the discussion

CVE-2026-72668 is a high-severity vulnerability in Elastic Kibana versions 9.4.0 through 9.4.6 involving an unintended proxy or intermediary ('Confused Deputy') issue in the Kibana Agent Builder. This flaw allows a non-administrative user who can edit a shared agent to cause privileged operations to be executed under the identity of a higher-privileged user. If the same user can also author workflows, this can escalate to full administrative control of Kibana and the Elasticsearch cluster.

Join the discussion

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without an Authorization identity and permits attacker-controlled Atlassian service headers, including X-Atlassian-Confluence-Url, to select a public attacker hostname or one allowed by MCP_ALLOWED_URL_DOMAINS. A caller can then invoke confluence_upload_attachment or the Jira attachment variant in src/mcp_atlassian/jira/attachments.py with a server-local file_path and cause the MCP process to send the file to the selected attachment endpoint. This issue is fixed in version 0.22.0.

Join the discussion

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementation without workspace validation. A caller can make the MCP server read arbitrary local files and attach them to a Jira issue, using the server as a confused deputy to exfiltrate the contents. The advisory traces the vulnerable input and processing flow through jira update_issue, attachments, upload_attachment, and file_path, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Join the discussion

Azure Arc Elevation of Privilege Vulnerability

Join the discussion

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v2/query/solr/ to its privileged Solr backend. An unauthenticated client can select the /admin/file handler, and SolrJ reformats the parameter into a request accepted even when handleSelect=false is configured on Solr 7.0 or later. When Solr returns the selected core configuration file, Metacat embeds the raw content in an XML processing error response, disclosing internal files such as solrconfig.xml and enabling infrastructure profiling. This issue is fixed in version 3.4.2.

Join the discussion

CVE-2026-45723 is an improper input validation vulnerability in siderolabs omni prior to versions 1.6.6 and 1.7.3. An authenticated Operator can manipulate the TalosVersion field to cause the application to issue HTTP GET requests to unintended paths on the configured image-factory host. This can lead to same-host endpoint probing and possible disclosure of internal diagnostic information. The vulnerability does not allow redirection to other hosts or write operations. The issue is fixed in versions 1.6.6 and 1.7.3.

Join the discussion

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and base64url-decodes the fonts parameter through decodeOgImageParams. Attacker-controlled fonts[].path values flow through loadDefinedFonts into the font-assets/node.js binding, which performs a server-side fetch without validating the URL scheme, origin, resolved address, or redirects. This permits blind requests to loopback, private, link-local, cloud metadata, and other internal HTTP services, while differences in the outer response status and timing can reveal service reachability. Slow targets can also occupy OG image render workers for the configured fetch and render timeouts. This issue is fixed in version 6.7.0.

Join the discussion

Strimzi Kafka Operator versions prior to 1.0.1 contain an improper privilege management vulnerability. An attacker able to create a Kafka custom resource can manipulate the entityOperator's watchedNamespace field to cause the operator to create a Role with full Secret CRUD permissions in a target namespace. This Role is bound to a ServiceAccount in the attacker's namespace, allowing the attacker to mint tokens and access Secrets across namespaces where the operator has permissions. The vulnerability is fixed in versions 1.0.1 and 1.1.0 by disabling the watchedNamespace feature by default and requiring explicit enabling.

Join the discussion

Showing 1 to 10 of 50 results

Filters:Tag: cwe-441
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses