Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-228v-wc5r-j8m7 | OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStream |
Tue, 17 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 12 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Olivetin
Olivetin olivetin |
|
| Vendors & Products |
Olivetin
Olivetin olivetin |
Wed, 11 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can receive output from actions they are not allowed to view, resulting in broken access control and sensitive information disclosure. | |
| Title | OliveTin Unauthorized Action Output Disclosure via EventStream | |
| Weaknesses | CWE-284 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-12T19:47:37.664Z
Reserved: 2026-03-10T22:02:38.854Z
Link: CVE-2026-32102
Updated: 2026-03-12T19:47:34.884Z
Status : Analyzed
Published: 2026-03-11T21:16:16.167
Modified: 2026-03-17T15:34:48.810
Link: CVE-2026-32102
No data.
OpenCVE Enrichment
Updated: 2026-03-20T15:37:22Z
Github GHSA