
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A critical remote code execution vulnerability was identified in Crayfish's Hypercube component (GHSA-c2p2-hgjg-9r3f), affecting versions <= 4.0.0 of the islandora/crayfish Composer package. The vulnerability was discovered and published on February 12, 2025, allowing potential remote code execution through the X-Islandora-Args Header in web-accessible installations of Hypercube (GitHub Advisory).
The vulnerability has been assigned a Critical severity rating with a CVSS score of 9.5/10. The CVSS v4 metrics indicate Network attack vector, Low attack complexity, Present attack requirements, No privileges required, and No user interaction needed. The vulnerability impacts both vulnerable and subsequent systems with High ratings for Confidentiality, Integrity, and Availability. The vulnerability is associated with CWE-74 and CWE-150 weaknesses (GitHub Advisory).
The vulnerability enables remote code execution in web-accessible installations of Hypercube, potentially compromising system security. Both vulnerable and subsequent systems face high impacts on confidentiality, integrity, and availability, indicating severe potential consequences if successfully exploited (GitHub Advisory).
While no patch is currently available, the vulnerability can be mitigated by ensuring Hypercube is not directly accessible from the Internet. Organizations using official installation methods have Crayfish behind a firewall by default, requiring no additional action. Web server configuration can be modified to validate header structures, though this is only necessary for publicly exposed endpoints. Standard security practices should be maintained (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”