products-pluggableauthservice vulnerabilities
CVEs whose affected-version data names the products-pluggableauthservice package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2021-33507Medium· 6.1Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
▾ Sunlitproducts-cmfcore · products-cmfcoreEPSS 0.75%via OSV
CVE-2021-21336Medium· 6.5Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager
Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager
▾ Sunlitproducts-pluggableauthservice · products-pluggableauthserviceEPSS 1.5%via OSV
CVE-2021-21337Medium· 5.7PoCURL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
▾ Twilightproducts-pluggableauthservice · products-pluggableauthserviceEPSS 8.4%via OSV