Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    OESA-2022-1952
    Fix available
    Packages

    ntp

    Summary

    ntp security update

    Published
    23 Sept 2022
    OESA-2022-1950
    Fix available
    Packages

    ansible

    Summary

    ansible security update

    Published
    23 Sept 2022
    OESA-2022-1949
    Fix available
    Packages

    xorg-x11-server

    Summary

    xorg-x11-server security update

    Published
    23 Sept 2022
    OESA-2022-1948
    Fix available
    Packages

    redis6

    Summary

    redis6 security update

    Published
    23 Sept 2022
    OESA-2022-1947
    Fix available
    Packages

    lapack

    Summary

    lapack security update

    Published
    23 Sept 2022
    OESA-2022-1946
    Fix available
    Packages

    logback

    Summary

    logback security update

    Published
    23 Sept 2022
    OESA-2022-1945
    Fix available
    Packages

    python-pip

    Summary

    python-pip security update

    Published
    23 Sept 2022
    OESA-2022-1944
    Fix available
    Packages

    python-pip

    Summary

    python-pip security update

    Published
    23 Sept 2022
    OESA-2022-1943
    Fix available
    Packages

    flink

    Summary

    flink security update

    Published
    23 Sept 2022
    OESA-2022-1941
    Fix available
    Packages

    kernel

    Summary

    kernel security update

    Published
    23 Sept 2022
    OESA-2022-1940
    Fix available
    Packages

    kernel

    Summary

    kernel security update

    Published
    23 Sept 2022
    OESA-2022-1939
    Fix available
    Packages

    golang, golang, golang

    Summary

    golang security update

    Published
    23 Sept 2022
    OESA-2022-1938
    Fix available
    Packages

    shim, shim, shim

    Summary

    shim security update

    Published
    23 Sept 2022
    OESA-2022-1934
    Fix available
    Packages

    rubygem-bundler

    Summary

    rubygem-bundler security update

    Published
    23 Sept 2022
    OESA-2022-1929
    Fix available
    Packages

    grafana

    Summary

    grafana security update

    Published
    23 Sept 2022
    OESA-2022-1937
    Fix available
    Packages

    gfbgraph

    Summary

    gfbgraph security update

    Published
    23 Sept 2022
    OESA-2022-1936
    Fix available
    Packages

    docker, docker, docker

    Summary

    docker security update

    Published
    23 Sept 2022
    OESA-2022-1935
    Fix available
    Packages

    libtiff, libtiff, libtiff

    Summary

    libtiff security update

    Published
    23 Sept 2022
    OESA-2022-1933
    Fix available
    Packages

    nodejs

    Summary

    nodejs security update

    Published
    23 Sept 2022
    OESA-2022-1932
    Fix available
    Packages

    expat, expat, expat

    Summary

    expat security update

    Published
    23 Sept 2022
    OESA-2022-1931
    Fix available
    Packages

    mailman

    Summary

    mailman security update

    Published
    23 Sept 2022
    OESA-2022-1930
    Fix available
    Packages

    netty

    Summary

    netty security update

    Published
    23 Sept 2022
    OESA-2022-1928
    Fix available
    Packages

    libconfuse, libconfuse, libconfuse

    Summary

    libconfuse security update

    Published
    23 Sept 2022
    SUSE-SU-2022:3350-1
    Fix available
    Packages

    kgraft-patch-SLE12-SP5_Update_24, kgraft-patch-SLE12-SP5_Update_25, kgraft-patch-SLE12-SP5_Update_24, kgraft-patch-SLE12-SP5_Update_25

    Summary

    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP5)

    Published
    23 Sept 2022
    PYSEC-2022-290
    Fix available
    Packages

    rdiffweb

    Summary

    Published
    23 Sept 2022
    CVE-2022-33683
    Fix available
    Packages

    Summary

    Disabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack

    Published
    23 Sept 2022
    CVE-2022-33682
    Fix available
    Packages

    Summary

    Disabled Hostname Verification makes Brokers, Proxies vulnerable to MITM attack

    Published
    23 Sept 2022
    CVE-2022-33681
    Fix available
    Packages

    Summary

    Improper Hostname Verification in Java Client and Proxy can expose authentication data via MITM

    Published
    23 Sept 2022
    CVE-2022-24280
    Fix available
    Packages

    Summary

    Apache Pulsar Proxy target broker address isn't validated

    Published
    23 Sept 2022
    CVE-2022-3269
    Fix available
    Packages

    Summary

    Session Fixation in ikus060/rdiffweb

    Published
    23 Sept 2022
    SUSE-SU-2022:3347-1
    Fix available
    Packages

    rubygem-rack, rubygem-rack, rubygem-rack, rubygem-rack, rubygem-rack, rubygem-rack, rubygem-rack

    Summary

    Security update for rubygem-rack

    Published
    23 Sept 2022
    CVE-2022-26112
    Fix available
    Packages

    Summary

    Pinot query endpoint and the realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support

    Published
    23 Sept 2022
    CVE-2022-39238
    Fix available
    Packages

    Summary

    Improper Authentication in Arvados when using PAM as identity provider

    Published
    23 Sept 2022
    CVE-2022-39239
    Fix available
    Packages

    Summary

    nefly-ipx subject to Server-Side Request Forgery and Stored Cross-Site Scripting via Cache Poisoning and Improper Host Validation

    Published
    23 Sept 2022
    CVE-2022-39231
    Fix available
    Packages

    Summary

    Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented

    Published
    23 Sept 2022
    SUSE-SU-2022:3346-1
    Fix available
    Packages

    kgraft-patch-SLE12-SP4_Update_27, kgraft-patch-SLE12-SP4_Update_29, kgraft-patch-SLE12-SP4_Update_27, kgraft-patch-SLE12-SP4_Update_29

    Summary

    Security update for the Linux Kernel (Live Patch 29 for SLE 12 SP4)

    Published
    23 Sept 2022
    SUSE-SU-2022:3342-1
    Fix available
    Packages

    kgraft-patch-SLE12-SP4_Update_23, kgraft-patch-SLE12-SP4_Update_24, kgraft-patch-SLE12-SP4_Update_25, kgraft-patch-SLE12-SP4_Update_23, kgraft-patch-SLE12-SP4_Update_24, kgraft-patch-SLE12-SP4_Update_25, kgraft-patch-SLE12-SP4_Update_23, kgraft-patch-SLE12-SP4_Update_24, kgraft-patch-SLE12-SP4_Update_25

    Summary

    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP4)

    Published
    23 Sept 2022
    AZL-11032
    Fix available
    Packages

    python-jwt

    Summary

    CVE-2022-39227 affecting package python-jwt for versions less than 2.4.0-2

    Published
    23 Sept 2022
    CVE-2022-39230
    Fix available
    Packages

    Summary

    Security issue in fhir-works-on-aws-authz-smart

    Published
    23 Sept 2022
    CVE-2022-39227
    Fix available
    Packages

    Summary

    Python-jwt subject to Authentication Bypass by Spoofing

    Published
    23 Sept 2022
    CVE-2022-39225
    Fix available
    Packages

    Summary

    Parse Server subject to Incorrect Resource Transfer Between Spheres

    Published
    23 Sept 2022
    Packages

    node-hoek, node-hoek, node-hoek

    Summary

    Published
    23 Sept 2022
    CVE-2020-36604
    Fix available
    Packages

    Summary

    Published
    23 Sept 2022
    UBUNTU-CVE-2020-36604
    No fix available
    Packages

    node-hoek, node-hoek

    Summary

    Published
    23 Sept 2022
    SUSE-SU-2022:3341-1
    Fix available
    Packages

    dpdk, dpdk-thunderx, dpdk, dpdk-thunderx

    Summary

    Security update for dpdk

    Published
    23 Sept 2022
    Packages

    kitty, kitty, kitty

    Summary

    Published
    23 Sept 2022
    CVE-2022-41320
    No fix available
    Packages

    Summary

    Published
    23 Sept 2022
    CVE-2022-41319
    No fix available
    Packages

    Summary

    Published
    23 Sept 2022
    Packages

    kitty

    Summary

    Published
    23 Sept 2022
    CVE-2022-41322
    Fix available
    Packages

    Summary

    Published
    23 Sept 2022