Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-hr8p-76q8-fxwq
    No fix available
    Packages

    org.jenkins-ci.plugins:performance

    Summary

    XXE vulnerability in Jenkins Performance Plugin

    Published
    24 May 2022
    GHSA-mj5v-ggjc-48p5
    Fix available
    Packages

    org.jenkins-ci.plugins:dependency-check-jenkins-plugin

    Summary

    XXE vulnerability in Jenkins OWASP Dependency-Check Plugin

    Published
    24 May 2022
    GHSA-rp4x-h577-chvq
    Fix available
    Packages

    org.biouno:uno-choice

    Summary

    Stored XSS vulnerability in Jenkins Active Choices Plugin

    Published
    24 May 2022
    GHSA-42q4-9xf9-f67x
    Fix available
    Packages

    apache-superset

    Summary

    Apache Superset allowed for database connections password leak for authenticated users

    Published
    24 May 2022
    GHSA-fc6h-769x-gff5
    No fix available
    Packages

    dolibarr/dolibarr

    Summary

    Dolibarr ERP and CRM contain XSS Vulnerability

    Published
    24 May 2022
    GHSA-vxr9-p2xw-m8cf
    Fix available
    Packages

    dolibarr/dolibarr

    Summary

    Dolibarr remote PHP code execution

    Published
    24 May 2022
    GHSA-mg2c-rc36-p594
    Fix available
    Packages

    github.com/apache/trafficcontrol, github.com/apache/trafficcontrol

    Summary

    Apache Traffic Control Traffic Ops Vulnerable to LDAP Injection

    Published
    24 May 2022
    GHSA-jgrp-6qqq-3284
    No fix available
    Packages

    Microsoft.ChakraCore

    Summary

    Chakra Scripting Engine and ChakraCore Vulnerable to Memory Corruption

    Published
    24 May 2022
    GHSA-xx36-6rv4-gj8r
    Fix available
    Packages

    ecdsa-elixir

    Summary

    ecdsa-elixir fails to check signatures, vulnerable to message forging

    Published
    24 May 2022
    GHSA-m3x9-623g-35c4
    Fix available
    Packages

    routinator

    Summary

    Routinator infinite loop vulnerability

    Published
    24 May 2022
    GHSA-4g38-hrm4-rg94
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-2c79-h2h5-g3fw
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-3q84-vrvx-rfvf
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-58xm-mxjf-254g
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-8xg4-xq2v-v6j7
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-929w-q433-4h9x
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-97c3-w9cr-6qc2
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-j3cq-h6vh-gx7f
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-m9hr-259f-2v23
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-pgj6-jmj5-wqfx
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-c5r9-rx53-q3gf
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Agent-to-controller access control allowed writing to sensitive directory used by Jenkins Pipeline: Shared Groovy Libraries Plugin

    Published
    24 May 2022
    GHSA-cv2w-q8c3-xjv7
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Agent-to-controller access control allows reading/writing most content of build directories in Jenkins

    Published
    24 May 2022
    GHSA-cvvm-4cr9-r436
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

    Published
    24 May 2022
    GHSA-q58j-fhj7-j6fg
    Fix available
    Packages

    org.jenkins-ci.plugins:subversion

    Summary

    Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files

    Published
    24 May 2022
    GHSA-xfg5-vrmc-24wc
    Fix available
    Packages

    obsidian-dataview

    Summary

    Obsidian Dataview vulnerable to code injection due to unsafe eval

    Published
    24 May 2022
    GHSA-3hw2-h67c-wq66
    Fix available
    Packages

    com.typesafe.akka:akka-http-core_2.13.0-RC3, com.typesafe.akka:akka-http-core_2.13.0-RC2, com.typesafe.akka:akka-http-core_2.13.0-M5, com.typesafe.akka:aakka-http-core_2.13.0-M3, com.typesafe.akka:akka-http-core_2.13, com.typesafe.akka:akka-http-core_2.13, com.typesafe.akka:akka-http-core_2.12, com.typesafe.akka:akka-http-core_2.12, com.typesafe.akka:akka-http-core_2.11

    Summary

    Uncontrolled Recursion in Akka HTTP

    Published
    24 May 2022
    GHSA-rfmp-97jj-h8m6
    Fix available
    Packages

    org.springframework:spring-core, org.springframework:spring-core, org.springframework:spring, org.springframework:spring

    Summary

    Improper Output Neutralization for Logs in Spring Framework

    Published
    24 May 2022
    GHSA-4926-qpxg-6r3w
    Fix available
    Packages

    org.springframework.data:spring-data-rest-core, org.springframework.data:spring-data-rest-core

    Summary

    Exposure of Resource to Wrong Sphere in Spring Data REST

    Published
    24 May 2022
    GHSA-fx7f-rjqj-52pj
    Fix available
    Packages

    org.springframework.amqp:spring-amqp, org.springframework.amqp:spring-amqp

    Summary

    Deserialization of Untrusted Data in Spring AMQP

    Published
    24 May 2022
    GHSA-pf94-6v2v-cm3j
    Fix available
    Packages

    org.springframework.cloud:spring-cloud-openfeign-core, org.springframework.cloud:spring-cloud-openfeign-core

    Summary

    Exposure of Resource to Wrong Sphere in Spring Cloud OpenFeign

    Published
    24 May 2022
    GHSA-cv24-vh45-4hjm
    No fix available
    Packages

    froxlor/froxlor

    Summary

    Foxlor cross-site scripting (XSS) vulnerability

    Published
    24 May 2022
    GHSA-g4rg-993r-mgx7
    Fix available
    Packages

    shell-quote

    Summary

    Improper Neutralization of Special Elements used in a Command in Shell-quote

    Published
    24 May 2022
    GHSA-w6f2-8wx4-47r5
    Fix available
    Packages

    mysql:mysql-connector-java

    Summary

    Incorrect Authorization in MySQL Connector Java

    Published
    24 May 2022
    GHSA-r2w2-h6r8-3r53
    Fix available
    Packages

    camaleon_cms

    Summary

    Camaleon CMS vulnerable to Uncaught Exception

    Published
    24 May 2022
    GHSA-vx6p-q4gj-x6xx
    Fix available
    Packages

    camaleon_cms

    Summary

    Camaleon CMS vulnerable to Server-Side Request Forgery

    Published
    24 May 2022
    GHSA-5gq7-826w-8282
    Fix available
    Packages

    grumpydictator/firefly-iii

    Summary

    Unrestricted File Upload vulnerability in Firefly III

    Published
    24 May 2022
    GHSA-8gf7-w3cp-gfh3
    Fix available
    Packages

    edu.stanford.nlp:stanford-corenlp

    Summary

    Improper Restriction of XML External Entity Reference in Stanford CoreNLP

    Published
    24 May 2022
    GHSA-f8vc-f28w-x9c9
    Fix available
    Packages

    apache-superset

    Summary

    Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page

    Published
    24 May 2022
    GHSA-pg8m-4p8j-2p56
    Fix available
    Packages

    apache-superset

    Summary

    Apache Superset SQL Injection when template processing is enabled

    Published
    24 May 2022
    GHSA-5h9g-8xcv-qjq9
    Fix available
    Packages

    edu.stanford.nlp:stanford-corenlp

    Summary

    Improper Restriction of XML External Entity Reference in Stanford CoreNLP

    Published
    24 May 2022
    GHSA-94wq-87g6-8h77
    Fix available
    Packages

    magento/community-edition, magento/community-edition, magento/community-edition, magento/community-edition, magento/project-community-edition

    Summary

    Magento Open Source allows Cross-Site Request Forgery (CSRF)

    Published
    24 May 2022
    GHSA-x23q-4j9j-9cxw
    Fix available
    Packages

    ops-cli

    Summary

    Ops CLI Deserialization of Untrusted Data vulnerability

    Published
    24 May 2022
    GHSA-6fvw-x6gw-4wv8
    Fix available
    Packages

    froxlor/froxlor

    Summary

    Froxlor SQL injection vulnerability

    Published
    24 May 2022
    GHSA-c8wv-qwwc-6j73
    Fix available
    Packages

    mediawiki/core

    Summary

    MediaWiki allows a denial of service

    Published
    24 May 2022
    GHSA-4pw5-r58h-fv24
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Path traversal vulnerability on Windows in Jenkins

    Published
    24 May 2022
    GHSA-6q4g-84f3-mw74
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Improper handling of equivalent directory names on Windows in Jenkins

    Published
    24 May 2022
    GHSA-gghc-g8cj-4vfv
    Fix available
    Packages

    org.jenkins-ci.plugins:git

    Summary

    Stored XSS vulnerability in Jenkins Git Plugin

    Published
    24 May 2022
    GHSA-w6pv-c757-6rgr
    Fix available
    Packages

    apollo_upload_server

    Summary

    apollo_upload_server has Denial of Service vulnerability

    Published
    24 May 2022
    GHSA-4258-vcjw-wwxx
    No fix available
    Packages

    openvpn-monitor

    Summary

    furlongm openvpn-monitor command injection

    Published
    24 May 2022
    GHSA-5w5c-3g26-8mmc
    No fix available
    Packages

    openvpn-monitor

    Summary

    furlongm openvpn-monitor allows Authorization Bypass to disconnect arbitrary clients

    Published
    24 May 2022