Open Source Vulnerabilities
Signature bypass via multiple root elements in node-SAML
Improper Neutralization of Alternate XSS Syntax in Knowage-Server
Improper Neutralization of Alternate XSS Syntax in Knowage-Server
Istio vulnerable to denial of service attack due to Golang Regex Library
Istio vulnerable to denial of service attack due to Golang Regex Library
Grafana users with email as a username can block other users from signing in
Grafana users with email as a username can block other users from signing in
Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins
Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins
Grafana data source and plugin proxy endpoints leaking authentication tokens to some destination plugins
Grafana data source and plugin proxy endpoints leaking authentication tokens to some destination plugins
Grafana plugin signature bypass vulnerability
Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters
Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters
October CMS Safe Mode bypass leads to authenticated RCE (Remote Code Execution)
October CMS Safe Mode bypass leads to authenticated RCE (Remote Code Execution)
Azure RTOS USBX Host PIMA vulnerable to read integer underflow with buffer overflow
Azure RTOS USBX Host PIMA vulnerable to read integer underflow with buffer overflow
,
Origin Validation Error in ikus060/rdiffweb
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
CVE-2022-3171 does not affect BellSoft software
freerdp, freerdp2, freerdp, freerdp2, freerdp2
freerdp, freerdp2, freerdp, freerdp2, freerdp2
protobuf, protobuf, protobuf, protobuf, protobuf
node-saml
Signature bypass via multiple root elements
passport-saml, node-saml, @node-saml/node-saml, @node-saml/passport-saml
Signature bypass via multiple root elements
passport-saml/ node-saml/ @node-saml/node-saml/ @node-saml/passport-saml
Signature bypass via multiple root elements
dropbear, dropbear, dropbear, dropbear
node-loader-utils, node-loader-utils, node-loader-utils
node-loader-utils/ node-loader-utils/ node-loader-utils
reaper
CVE-2022-37601 affecting package reaper for versions less than 3.1.1-3
reaper
CVE-2022-37601 affecting package reaper for versions less than 3.1.1-3
