Open Source Vulnerabilities
yiisoft/yii2-authclient
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
yiisoft/yii2-authclient
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
@sentry/astro
Sentry's Astro SDK vulnerable to ReDoS
yiisoft/yii2-authclient
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
yiisoft/yii2-authclient
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
resque
Resque vulnerable to Reflected Cross Site Scripting through pathnames
resque
Resque vulnerable to Reflected Cross Site Scripting through pathnames
resque
Resque vulnerable to reflected XSS in resque-web failed and queues lists
resque
Resque vulnerable to reflected XSS in resque-web failed and queues lists
resque
Resque vulnerable to reflected XSS in Queue Endpoint
resque
Resque vulnerable to reflected XSS in Queue Endpoint
malojaserver
Maloja error page XSS vulnerability
org.keycloak:keycloak-services
Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri
org.keycloak:keycloak-services
Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri
resque-scheduler
Resque Scheduler Reflected XSS In Delayed Jobs View
resque-scheduler
Resque Scheduler Reflected XSS In Delayed Jobs View
russh, golang.org/x/crypto, paramiko, golang.org/x/crypto
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
russh/ golang.org/x/crypto/ paramiko/ golang.org/x/crypto
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
asyncssh
AsyncSSH vulnerable to Prefix Truncation Attack (a.k.a. Terrapin Attack) against ChaCha20-Poly1305 and Encrypt-then-MAC
asyncssh
AsyncSSH vulnerable to Prefix Truncation Attack (a.k.a. Terrapin Attack) against ChaCha20-Poly1305 and Encrypt-then-MAC
zerocopy, zerocopy, zerocopy, zerocopy, zerocopy, zerocopy
Zerocopy: Some Ref methods are unsound with some type parameters
zerocopy/ zerocopy/ zerocopy/ zerocopy/ zerocopy/ zerocopy
Zerocopy: Some Ref methods are unsound with some type parameters
openssh, openssh, openssh, openssh, openssh, openssh, openssh, openssh
openssh/ openssh/ openssh/ openssh/ openssh/ openssh/ openssh/ openssh
openssh, openssh, openssh, openssh, openssh, openssh, openssh, openssh
openssh/ openssh/ openssh/ openssh/ openssh/ openssh/ openssh/ openssh
openssh
CVE-2023-51385 affecting package openssh for versions less than 8.9p1-3
openssh
CVE-2023-51385 affecting package openssh for versions less than 8.9p1-3
openssh
CVE-2023-51384 affecting package openssh for versions less than 8.9p1-3
openssh
CVE-2023-51384 affecting package openssh for versions less than 8.9p1-3
openssh
CVE-2023-51384 affecting package openssh for versions less than 9.7p1-1
openssh
CVE-2023-51384 affecting package openssh for versions less than 9.7p1-1
openssh
CVE-2023-51385 affecting package openssh for versions less than 9.7p1-1
openssh
CVE-2023-51385 affecting package openssh for versions less than 9.7p1-1
libsass, libsass, libsass, libsass
Security update for libsass
libsass/ libsass/ libsass/ libsass
Security update for libsass
dropbear, dropbear, dropbear, erlang, erlang, erlang, filezilla, filezilla, filezilla, golang-go.crypto, golang-go.crypto, golang-go.crypto, libssh, libssh, libssh, libssh2, libssh2, openssh, openssh, openssh, paramiko, paramiko, paramiko, php-phpseclib, php-phpseclib, php-phpseclib, php-phpseclib3, php-phpseclib3, php-phpseclib3, phpseclib, phpseclib, proftpd-dfsg, proftpd-dfsg, proftpd-dfsg, proftpd-mod-proxy, proftpd-mod-proxy, proftpd-mod-proxy, putty, putty, putty, python-asyncssh, python-asyncssh, python-asyncssh, tinyssh, tinyssh, tinyssh, trilead-ssh2, trilead-ssh2, trilead-ssh2
dropbear/ dropbear/ dropbear/ erlang/ erlang/ erlang/ filezilla/ filezilla/ filezilla/ golang-go.crypto/ golang-go.crypto/ golang-go.crypto/ libssh/ libssh/ libssh/ libssh2/ libssh2/ openssh/ openssh/ openssh/ paramiko/ paramiko/ paramiko/ php-phpseclib/ php-phpseclib/ php-phpseclib/ php-phpseclib3/ php-phpseclib3/ php-phpseclib3/ phpseclib/ phpseclib/ proftpd-dfsg/ proftpd-dfsg/ proftpd-dfsg/ proftpd-mod-proxy/ proftpd-mod-proxy/ proftpd-mod-proxy/ putty/ putty/ putty/ python-asyncssh/ python-asyncssh/ python-asyncssh/ tinyssh/ tinyssh/ tinyssh/ trilead-ssh2/ trilead-ssh2/ trilead-ssh2
dropbear, dropbear, dropbear, dropbear, dropbear, dropbear, dropbear, dropbear, dropbear, libssh2, libssh2, libssh2, libssh2, libssh2, libssh2, libssh2, libssh2, libssh2, openssh, openssh, openssh, openssh, openssh, openssh, openssh, openssh, openssh, putty, putty, putty, putty
dropbear/ dropbear/ dropbear/ dropbear/ dropbear/ dropbear/ dropbear/ dropbear/ dropbear/ libssh2/ libssh2/ libssh2/ libssh2/ libssh2/ libssh2/ libssh2/ libssh2/ libssh2/ openssh/ openssh/ openssh/ openssh/ openssh/ openssh/ openssh/ openssh/ openssh/ putty/ putty/ putty/ putty
python-paramiko
CVE-2023-48795 affecting package python-paramiko 2.12.0-2
python-paramiko
CVE-2023-48795 affecting package python-paramiko 2.12.0-2
cert-manager
CVE-2023-48795 affecting package cert-manager for versions less than 1.11.2-7
cert-manager
CVE-2023-48795 affecting package cert-manager for versions less than 1.11.2-7
erlang
CVE-2023-48795 affecting package erlang for versions less than 25.2-1
erlang
CVE-2023-48795 affecting package erlang for versions less than 25.2-1
libssh
CVE-2023-48795 affecting package libssh for versions less than 0.10.6-1
libssh
CVE-2023-48795 affecting package libssh for versions less than 0.10.6-1
libssh2
CVE-2023-48795 affecting package libssh2 for versions less than 1.9.0-4
libssh2
CVE-2023-48795 affecting package libssh2 for versions less than 1.9.0-4
nmap
CVE-2023-48795 affecting package nmap for versions less than 7.93-2
nmap
CVE-2023-48795 affecting package nmap for versions less than 7.93-2
openssh
CVE-2023-48795 affecting package openssh for versions less than 8.9p1-4
openssh
CVE-2023-48795 affecting package openssh for versions less than 8.9p1-4
kubernetes
CVE-2023-48795 affecting package kubernetes for versions less than 1.28.4-4
kubernetes
CVE-2023-48795 affecting package kubernetes for versions less than 1.28.4-4
kubevirt
CVE-2023-48795 affecting package kubevirt for versions less than 0.59.0-27
kubevirt
CVE-2023-48795 affecting package kubevirt for versions less than 0.59.0-27
