The Config Model Project maintains a narrowly scoped configuration management tool whose vulnerability footprint reflects the modest but notable security presence of tooling in this domain. The durable signal centers on the project's core product and the input-validation and access-control challenges typical of systems that parse and apply configuration data. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Config Model Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-0374HIGH lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to u | May 23, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-0373HIGH The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remot | May 23, 2017 | 7.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Config Model Project.
Media articles that mention a CVE ID that affects a product developed by Config Model Project — matched by CVE ID, not by vendor name.