Comparison Overview
Amazon Development Center Poland

Amazon Development Center Poland
Aleja Grunwaldzka 472, Gdansk, 80-309, PL
Last Update: 15/03/2026
Amazon Development Center Poland consists of three Technology Development Centers located in Gdańsk, Warsaw, and Krakow, where teams of female and male managers, engineers, and scientists create and develop Amazon's most advanced global technologies, such as: Alexa, Rin...

Sage
North Park, Newcastle upon Tyne, GB, NE13 9AA
Last Update: 02/04/2026
At Sage, we knock down barriers with information, insights, and tools to help your business flow. We provide businesses with software and services that are simple and easy to use, as we work with you to give you that feeling of confidence. Customers trust our Payroll,...
Compliance Ranges Comparison

Amazon Development Center Poland







Sage






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for Amazon Development Center Poland in 2026.
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for Sage in 2026.
Incident History - Amazon Development Center Poland (X = Date, Y = Severity)
Amazon Development Center Poland cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Sage (X = Date, Y = Severity)
Sage cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Amazon Development Center Poland

Sage
FAQ
Latest Global CVEs
A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods in multi-cluster deployments. This issue is fixed in versions 1.0.2 and 1.1.2.
- https://github.com/openchoreo/openchoreo/commit/047d80ddc63b4b4b9dd67044d5cffcdbd77685ce
- https://github.com/openchoreo/openchoreo/commit/0aa0ffe1623bd8eb4235cb2a5854336695953c3a
- https://github.com/openchoreo/openchoreo/commit/b42eeb0f5dce95195a9781d7c5a1fe9e38f5da8f
- https://github.com/openchoreo/openchoreo/pull/4122
- https://github.com/openchoreo/openchoreo/releases/tag/v1.0.2
- https://github.com/openchoreo/openchoreo/releases/tag/v1.1.2
- https://github.com/openchoreo/openchoreo/security/advisories/GHSA-qh9r-j7rp-4x2m
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.
- https://github.com/openchoreo/openchoreo/commit/50fcae3f1753fd0ac3ae655a3fc080a761c49c04
- https://github.com/openchoreo/openchoreo/commit/93e6f10953cfc249af2222ddb6730d4b0a729129
- https://github.com/openchoreo/openchoreo/commit/e3da3c63dcf0895c693cb17ce142ef95e959b62a
- https://github.com/openchoreo/openchoreo/pull/4256
- https://github.com/openchoreo/openchoreo/pull/4258
- https://github.com/openchoreo/openchoreo/pull/4259
- https://github.com/openchoreo/openchoreo/releases/tag/v1.0.3
- https://github.com/openchoreo/openchoreo/releases/tag/v1.1.3
- https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0-rc.2
- https://github.com/openchoreo/openchoreo/security/advisories/GHSA-rh53-xvx2-j327
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.2.0.