Vulnerabilities
Vulnerable Software
Cribl:  >> Cribl Stream  >> 4.3.1  Security Vulnerabilities
Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.
CVSS Score
8.7
EPSS Score
0.006
Published
2026-07-27
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.
CVSS Score
8.7
EPSS Score
0.004
Published
2026-07-27


Contact Us

Shodan ® - All rights reserved