Ontrack Project maintains a specialized configuration and deployment-management tool centered on its single Ontrack product, which serves a focused user base in enterprise build and release automation. The recurring vulnerability pattern centers on authentication and credential-handling weaknesses, including improper authentication logic and insufficient password-hashing computational effort, reflecting the access-control and secrets-management demands of a deployment orchestration platform. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ontrack Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37164CRITICAL Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user pass | Sep 8, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ontrack Project.
Media articles that mention a CVE ID that affects a product developed by Ontrack Project — matched by CVE ID, not by vendor name.