Scalyr is a focused vendor providing agent-based log collection and monitoring software, with its exposure centered on the Scalyr Agent product and its cryptographic validation mechanisms. The durable signal across its disclosures reflects improper certificate validation, a weakness class endemic to agents that communicate with remote collection endpoints over TLS. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scalyr over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24714CRITICAL The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option. | Aug 27, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-24715CRITICAL The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonNa | Aug 27, 2020 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scalyr.
Media articles that mention a CVE ID that affects a product developed by Scalyr — matched by CVE ID, not by vendor name.