Sphinxsearch Sphinx vulnerabilities
2 known vulnerabilities affecting sphinxsearch/sphinx.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-29050HIGHCVSS 7.5≤ 3.1.12022-01-10
CVE-2020-29050 [HIGH] CVE-2020-29050: SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx.
nvd
CVE-2019-14511HIGHCVSS 7.5v3.1.12019-08-22
CVE-2019-14511 [HIGH] CWE-306 CVE-2019-14511: Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
nvd