Blockchain Platform
Vendor:
First CVE: May 29, 2017 · Active for 9 years
40
Total CVEs
More Total CVEs than 97% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Blockchain Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2017
9 years ago
Most Recent CVE
Jul 21, 2021
1,830 days ago
CVE Severity & Scoring
Blockchain Platform40 CVEs
20%
80%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (2.5%)
Network39 (97.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (35.0%)
High26 (65.0%)
Unknown0 (0.0%)
User Interaction
None36 (90.0%)
Unknown0 (0.0%)
Required4 (10.0%)
Privileges Required
Low3 (7.5%)
High1 (2.5%)
None36 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11023MEDIUM In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's | Apr 29, 2020 | 6.1 | 95 | YES | YES |
CVE-2020-11022MEDIUM In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append | Apr 29, 2020 | 6.1 | 83 | NO | YES |
CVE-2020-13935HIGH The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl | Jul 14, 2020 | 7.5 | 77 | NO | YES |
CVE-2021-23017HIGH A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in | Jun 1, 2021 | 7.7 | 65 | NO | YES |
CVE-2020-8277HIGH A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 b | Nov 19, 2020 | 7.5 | 54 | NO | NO |
CVE-2019-10086HIGH In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property | Aug 20, 2019 | 7.3 | 40 | NO | NO |
CVE-2020-36179HIGH FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapte | Jan 7, 2021 | 8.1 | 36 | NO | NO |
CVE-2020-17527HIGH While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the | Dec 3, 2020 | 7.5 | 34 | NO | NO |
CVE-2020-25649HIGH A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi | Dec 3, 2020 | 7.5 | 34 | NO | NO |
CVE-2020-35728HIGH FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDICo | Dec 27, 2020 | 8.1 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
1 CVE
2.5% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.5% of CVEs· 96th percentile
ExploitDB
3 CVEs
7.5% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Blockchain Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 21.1.2 | 2 | 7.2 | 43.2% | 1 | 1 |