← back
CVE-2016-15036

Deis Workflow Manager race condition

CVSS 4.6 MEDIUMEPSS 0.4%CWE-362
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.6EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
23 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Deis Workflow Manager up to 2.3.2. It has been classified as problematic. This affects an unknown part. The manipulation leads to race condition. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 2.3.3 is able to address this issue. The patch is named 31fe3bccbdde134a185752e53380330d16053f7f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248847. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
Deis · Workflow Manager

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →