Rdbrck develops a focused product line centered on its Shift platform, which handles credential and secret management for infrastructure environments. The vendor's vulnerability profile concentrates on storage and access-control weaknesses—including insecure storage of sensitive information, insufficiently protected credentials, and untrusted search paths—that reflect the security-critical nature of secrets management. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rdbrck over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12914HIGH Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. | Jul 17, 2019 | 7.5 | 22 | NO | NO |
CVE-2019-12911HIGH Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. | Jul 17, 2019 | 7.5 | 21 | NO | NO |
CVE-2019-8932HIGH Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. | Jul 17, 2019 | 7.5 | 19 | NO | NO |
CVE-2019-8931HIGH Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application. | Jul 17, 2019 | 7.5 | 19 | NO | NO |
CVE-2019-12913MEDIUM Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application. | Jul 17, 2019 | 5.5 | 18 | NO | NO |
CVE-2019-12912MEDIUM Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application. | Jul 17, 2019 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rdbrck.
Media articles that mention a CVE ID that affects a product developed by Rdbrck — matched by CVE ID, not by vendor name.