Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host header can be manipulated.
Publication date: Fri, 09 May 2025 00:00:00 +0000
Cyber News related to CVE-2025-47424
CVE-2025-47424 - Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host header can be manipulated. ...
10 months ago
CVE-2021-47424 - In the Linux kernel, the following vulnerability has been resolved: i40e: Fix freeing of uninitialized misc IRQ vector When VSI set up failed in i40e_probe() as part of PF switch set up driver was trying to free misc IRQ vectors in ...
1 year ago Tenable.com
CVE-2024-47424 - Integer Overflow or Wraparound (CWE-190) potentially leading to Arbitrary code execution ...
1 year ago Tenable.com
CVE-2022-47424 - Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARMember, Repute InfoSystems ARMember Premium allows Cross-Site Request Forgery.This issue affects ARMember: from n/a through 4.0.5; ARMember Premium: from n/a before 6.7.1. ...
1 year ago Tenable.com