Shrinerb develops the Shrine digital asset management and preservation platform, a narrowly scoped product used in archival and institutional contexts. Its observed vulnerability profile centers on observable discrepancies and timing-based side channels, reflecting the information-disclosure risks inherent to systems handling sensitive metadata and access controls. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shrinerb over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15237MEDIUM In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a timing attack to guess the signature of the derivation URL. The | Oct 5, 2020 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shrinerb.
Media articles that mention a CVE ID that affects a product developed by Shrinerb — matched by CVE ID, not by vendor name.