Oneshield's vulnerability footprint is concentrated in its policy management product and characterized by application-layer input-handling issues, primarily code injection and cross-site scripting weaknesses that arise from inadequate input validation and output encoding in web-facing components. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oneshield over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11642HIGH A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authenticated remote adversaries can poison log files by entering m | May 8, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-11643MEDIUM Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type s | May 8, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oneshield.
Media articles that mention a CVE ID that affects a product developed by Oneshield — matched by CVE ID, not by vendor name.