📦 Fides

by Ethyca

🔍 What is Fides?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-45053

CRITICAL CVSS 9.1 Sep 4, 2024

This CVE describes a Server-Side Template Injection vulnerability in Fides privacy platform's Email Templating feature. It allows privileged users (Owners or Contributors) to execute arbitrary code on...

CVE-2025-57816

HIGH CVSS 7.5 Sep 8, 2025

This vulnerability allows attackers to bypass rate limiting protections in Fides privacy engineering platform deployments that rely on its built-in IP-based rate limiting. It affects environments usin...

CVE-2023-48224

HIGH CVSS 8.2 Nov 15, 2023

This vulnerability in the Fides privacy platform allows attackers to predict one-time verification codes due to weak random number generation. Attackers can submit verified data erasure requests to de...

CVE-2023-46124

HIGH CVSS 8.2 Oct 25, 2023

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Fides privacy engineering platform. Attackers can upload malicious YAML files in custom integrations to make arbitrary requ...

CVE-2023-41319

HIGH CVSS 8.8 Sep 6, 2023

This vulnerability allows authenticated, highly-privileged users to bypass the sandbox environment in Fides webserver API and execute arbitrary code with root privileges. It affects Fides versions 2.1...

CVE-2023-36827

HIGH CVSS 7.5 Jul 5, 2023

CVE-2023-36827 is a path traversal vulnerability in Fides privacy engineering platform that allows remote attackers to read arbitrary files on the webserver container's filesystem. This affects Fides ...

CVE-2025-57815

MEDIUM CVSS 6.5 Sep 8, 2025

Fides Admin UI login endpoint lacks specific anti-automation controls, allowing attackers to conduct credential testing attacks like brute-force, credential stuffing, or password spraying. This affect...

CVE-2024-45052

MEDIUM CVSS 5.3 Sep 4, 2024

This vulnerability allows unauthenticated attackers to determine valid usernames in Fides privacy platform by measuring timing differences in authentication responses. Attackers can use this informati...