CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When KNIME Analytics Platform is used as an executor for either KNIME Server or KNIME Business Hub severa...Show more |
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files being overwritten on the user's system. This vulnerability is also know...Show more |
1Knime 1Knime Analytics Platform Nov 21, 2024 Jun 2, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions. |
1Knime 1Knime Analytics Platform Nov 21, 2024 Dec 16, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730. |