The Hive Project maintains a focused security-operations platform centered on incident response and threat analysis, with its vulnerability footprint concentrated in products such as Cortex and its associated analyzers. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thehive Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7652HIGH TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, selec | May 9, 2019 | 7.7 | 30 | NO | YES |
CVE-2018-20226HIGH An organization administrator can add a super administrator in THEHIVE PROJECT Cortex before 2.1.3 due to the lack of overriding the Role.toString method. | Dec 21, 2018 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thehive Project.
Media articles that mention a CVE ID that affects a product developed by Thehive Project — matched by CVE ID, not by vendor name.