Mozilla Hubs Cloud vulnerabilities
2 known vulnerabilities affecting mozilla/hubs_cloud.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-29979MEDIUMCVSS 6.1≥ unspecified, < mozillareality/reticulum/1.0.1/202106180126342021-08-02
CVE-2021-29979 [MEDIUM] CWE-79 CVE-2021-29979: Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow java
Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s primary hosting domain.*. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210618012634.
nvd
CVE-2021-29954CRITICALCVSS 9.8≥ unspecified, < mozillareality/reticulum/1.0.1/202104282012552021-06-24
CVE-2021-29954 [CRITICAL] CWE-312 CVE-2021-29954: Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, incl
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210428201255.
nvd