Ory
7 known vulnerabilities
Top Products
Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versio
Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelat
Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the Li
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o
Frequently Asked Questions
How many CVEs affect Ory?
Ory has 7 CVE records in our database, including 1 critical and 5 high severity vulnerabilities.
What are the most severe Ory vulnerabilities?
Ory has 1 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Ory vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Ory products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Ory Vulnerabilities
CyberStrike scans your infrastructure for Ory vulnerabilities and provides real-time remediation guidance.
Get Started