Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Inedo

First CVE: Sep 30, 2017Active for: 9 yearsTotal CVEs: 9

Inedo develops a focused suite of build-automation, configuration-management, and package-management tools (BuildMaster, Otter, and ProGet) that operate in critical infrastructure-deployment pipelines, and its vulnerabilities skew strongly toward critical-severity outcomes. The exposure recurs through web-application and access-control weakness classes including improper input validation, cross-site scripting, path traversal, cross-site request forgery, and improper privilege management, reflecting the authenticated-user and administrative-access context of these deployment-tier products. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Inedo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2017
8 years ago
Most Recent CVE
May 3, 2025
448 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-15607CRITICAL
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.
Dec 1, 20179.830NONO
CVE-2017-16521CRITICAL
In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
Nov 10, 20179.830NONO
CVE-2017-17086CRITICAL
Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecifi
Dec 1, 20179.829NONO
CVE-2017-16520HIGH
Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
Nov 11, 20177.524NONO
CVE-2017-14944HIGH
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.
Sep 30, 20177.524NONO
CVE-2017-15608MEDIUM
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Sep 26, 20186.522NONO
CVE-2025-47244HIGH
Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an atta
May 3, 20257.321NONO
CVE-2017-16761MEDIUM
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
Nov 10, 20176.121NONO
CVE-2017-16760MEDIUM
Inedo BuildMaster before 5.8.2 has XSS.
Nov 10, 20176.121NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
33%
33%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Inedo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Inedo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Inedo's Products

View all 1 CNAs →

Top CWEs