Trufflesecurity operates a focused credential and secret scanning tool, Trufflehog, designed to detect exposed sensitive data in code repositories and git history. The observed vulnerability signal centers on server-side request forgery, reflecting the tool's network-facing scanning capabilities. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trufflesecurity over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
TruffleHog is a secrets scanning tool. Prior to v3.81.9, this vulnerability allows a malicious actor to craft data in a way that, when scanned by specific detectors, could trigger | Aug 19, 2024 | 3.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trufflesecurity.
Media articles that mention a CVE ID that affects a product developed by Trufflesecurity — matched by CVE ID, not by vendor name.