Sandstorm
Sandstorm is a self-hosted, open-source platform for collaboration and application hosting that allows users to run third-party applications in isolated containers. Its observed vulnerability pattern centers on information disclosure, authentication weaknesses, server-side request forgery, and resource-consumption flaws, reflecting the complexity inherent in sandboxing untrusted application code and managing cross-application isolation boundaries. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Sandstorm over time
Products(1 total)
Top CVEs
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6199CRITICAL A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field. | Feb 6, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-6201HIGH A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could | Feb 6, 2018 | 8.1 | 24 | NO | NO |
CVE-2017-6200MEDIUM Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip functi | Feb 6, 2018 | 6.5 | 22 | NO | NO |
CVE-2017-6198MEDIUM The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by launching a fork bomb in the sand | Feb 6, 2018 | 6.5 | 20 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (4 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Sandstorm.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Sandstorm — matched by CVE ID, not by vendor name.