Trove

Vendor:

First CVE: Oct 8, 2014 · Active for 11 years

3
Total CVEs
More Total CVEs than 64% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
3.2
Avg CVSS
Higher Avg CVSS than 1% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Trove over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 8, 2014
11 years ago
Most Recent CVE
Aug 11, 2017
3,271 days ago

CVE Severity & Scoring

Trove3 CVEs
All CVEs352,713 CVEs
LowMedium
Attack Vector
Local1 (33.3%)
Network0 (0.0%)
Unknown2 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (33.3%)
High0 (0.0%)
Unknown2 (66.7%)
User Interaction
None1 (33.3%)
Unknown2 (66.7%)
Required0 (0.0%)
Privileges Required
Low1 (33.3%)
High0 (0.0%)
None0 (0.0%)
Unknown2 (66.7%)

Top CVEs

Signals from CVEs in this product scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/experimental/postgresql/service
Aug 11, 20175.516NONO
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when
Oct 8, 20142.111NONO
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from comman
Oct 8, 20142.111NONO

Exploit Exposure

Signals from CVEs in this product scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (3 CVEs).

Media Mentions

Signals from CVEs in this product scope (3 CVEs).

Top CNAs Publishing CVEs For Trove

Top CWEs

Versions

No cataloged versions.