← Back

Newrelic

newrelic

3 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Ruby Agent
ruby_agent
.net Agent
.net_agent
Nozzle
nozzle
Service Broker
service_broker

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
27Anynines
ApigeeAppdynamics+24 more
55Application Analytics
Application MonitoringApplication Performance Monitoring+52 more
Jun 17, 2026
Aug 5, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.Show less
1Newrelic
1.net Agent
May 13, 2026
Jun 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES...Show more
New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLAN_ALL ON protection mechanism.Show less
1Newrelic
1Ruby Agent
Apr 29, 2026
Apr 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by s...Show more
Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data.Show less