Skip to main content

Vendor/product archive

ethyca / fides CVEs

Beta · best-effort

20 CVEs tagged to ethyca / fides1 Critical, 5 High, 6 Medium, 7 Low, 1 Unrated.

CVE-2025-57817

Published Sep 8, 2025

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-57816

Published Sep 8, 2025

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs,…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57815

Published Sep 8, 2025

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and la…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-57766

Published Sep 8, 2025

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vulnerabi…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52008

Published Nov 26, 2024

Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-45053

Published Sep 4, 2024

Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitiz…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45052

Published Sep 4, 2024

Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vul…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31223

Published Jul 3, 2024

Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to commu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38537

Published Jul 2, 2024

Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domai…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2024-35189

Published May 30, 2024

Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets`…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34715

Published May 29, 2024

Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL database for persistent storage of application data. If the…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48224

Published Nov 15, 2023

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47114

Published Nov 8, 2023

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in your runtime environment, and the enforcement of privacy regulations…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46126

Published Oct 25, 2023

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, helping enforce privacy regulations in code. Th…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-46125

Published Oct 25, 2023

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46124

Published Oct 25, 2023

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in c…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41319

Published Sep 6, 2023

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37481

Published Jul 18, 2023

Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fides webserver is vulnerable to a type of Denial of Service (…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37480

Published Jul 18, 2023

Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fides webserver is vulnerable to a type of Denial of Service (…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-36827

Published Jul 5, 2023

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1