Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-5c2c-cvg6-ghjm
    Fix available
    Packages

    org.jenkins-ci.plugins:nomad

    Summary

    Password stored in plain text by Jenkins Nomad Plugin

    Published
    24 May 2022
    GHSA-5wc4-w63v-97c3
    Fix available
    Packages

    org.jenkins-ci.plugins:nested-view

    Summary

    XXE vulnerability in Jenkins Nested View Plugin

    Published
    24 May 2022
    GHSA-x77r-7m5w-pqq2
    Fix available
    Packages

    org.jenkins-ci.plugins:azure-ad

    Summary

    Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL

    Published
    24 May 2022
    GHSA-fh73-gjvg-349c
    Fix available
    Packages

    neutron, neutron, neutron

    Summary

    OpenStack Neutron vulnerable to authenticated attackers reconfiguring dnsmasq via crafted extra_dhcp_opts value

    Published
    24 May 2022
    GHSA-fpv7-hx6r-9vcx
    No fix available
    Packages

    mezzanine

    Summary

    Mezzanine Cross Site Scripting (XSS) vulnerability

    Published
    24 May 2022
    GHSA-5ww6-px42-wc85
    Fix available
    Packages

    openssl-src

    Summary

    SM2 Decryption Buffer Overflow

    Published
    24 May 2022
    GHSA-q9wj-f4qw-6vfj
    Fix available
    Packages

    openssl-src

    Summary

    Read buffer overruns processing ASN.1 strings

    Published
    24 May 2022
    GHSA-hvm4-mc7m-22w4
    Fix available
    Packages

    neutron, neutron, neutron

    Summary

    OpenStack Neutron vulnerable to hardware address impersonation

    Published
    24 May 2022
    GHSA-jx66-5ww9-m6q4
    Fix available
    Packages

    org.owasp:csrfguard

    Summary

    Cross-Site Request Forgery in OWASP CSRFGuard

    Published
    24 May 2022
    GHSA-h6r2-pgvx-683c
    No fix available
    Packages

    lin-cms

    Summary

    Lin-CMS-Flask vulnerable to Improper Authentication

    Published
    24 May 2022
    GHSA-rvf8-c35m-8289
    No fix available
    Packages

    lin-cms

    Summary

    Lin-CMS-Flask Cross Site Scripting (XSS) vulnerability

    Published
    24 May 2022
    GHSA-45mx-g85m-wwm3
    Fix available
    Packages

    obsidian

    Summary

    Obsidian does not require user confirmation for non-http/https URLs.

    Published
    24 May 2022
    GHSA-jf7x-57g8-9hm5
    No fix available
    Packages

    org.jeecgframework.boot:jeecg-boot-parent

    Summary

    Jeecg-Boot CMS arbitrary file upload vulnerability

    Published
    24 May 2022
    GHSA-jj94-j4r3-5gr4
    Fix available
    Packages

    intelliants/subrion

    Summary

    Subrion Cross-Site Scripting (XSS) vulnerability

    Published
    24 May 2022
    GHSA-4225-97pr-rr52
    Fix available
    Packages

    keystone, keystone, keystone, keystone

    Summary

    OpenStack Keystone allows information disclosure during account locking

    Published
    24 May 2022
    GHSA-5499-qjvh-6j7w
    Fix available
    Packages

    org.wildfly.security:wildfly-elytron, org.wildfly.security:wildfly-elytron, org.wildfly.security:wildfly-elytron

    Summary

    Observable Discrepancy in Wildfly Elytron

    Published
    24 May 2022
    GHSA-5gh9-g62h-f35m
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers

    Published
    24 May 2022
    GHSA-4frg-rpx6-96qh
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs

    Published
    24 May 2022
    GHSA-7pxh-q6jw-6xj8
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting

    Published
    24 May 2022
    GHSA-fvg6-9r88-7w85
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)

    Published
    24 May 2022
    GHSA-9h7f-5hc8-cj5f
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay:com.liferay.frontend.taglib.clay

    Summary

    Liferay Portal cross-site scripting (XSS) vulnerability in the Frontend Taglib module

    Published
    24 May 2022
    GHSA-v88g-7fx4-9q7f
    Fix available
    Packages

    com.liferay:com.liferay.document.library.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module

    Published
    24 May 2022
    GHSA-mrmf-755g-w2vw
    Fix available
    Packages

    joplin

    Summary

    Joplin vulnerable to Cross-site Scripting in notes

    Published
    24 May 2022
    GHSA-59gp-qqm7-cw4j
    Fix available
    Packages

    nokogiri

    Summary

    Nokogiri has vulnerable dependencies on libxml2 and libxslt

    Published
    24 May 2022
    GHSA-22wc-7wmm-v4cc
    Fix available
    Packages

    com.liferay:com.liferay.portlet.configuration.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP does not properly check user permission

    Published
    24 May 2022
    GHSA-474f-cmx5-gm69
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Don't Check Permissions of Pages

    Published
    24 May 2022
    GHSA-6c88-gvxw-f5hg
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Stores User Passwords in Cleartext

    Published
    24 May 2022
    GHSA-fxpf-jr2q-vpvv
    Fix available
    Packages

    com.liferay:com.liferay.dynamic.data.mapping.form.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP autosaves form data for other users to see

    Published
    24 May 2022
    GHSA-hgjv-7wjr-qwqp
    Fix available
    Packages

    com.liferay:com.liferay.frontend.js.aui.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module

    Published
    24 May 2022
    GHSA-jfch-m2x3-2v66
    Fix available
    Packages

    com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom

    Summary

    Liferay Portal and Liferay DXP insecure default configuration

    Published
    24 May 2022
    GHSA-vpvm-3wfw-5f5c
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page

    Published
    24 May 2022
    GHSA-wg4x-hf94-fj5v
    Fix available
    Packages

    com.liferay:com.liferay.flags.taglib, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate

    Published
    24 May 2022
    GHSA-9995-qvcg-x7g6
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)

    Published
    24 May 2022
    GHSA-g37f-j8hh-736f
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Fails to Properly Check User Permissions

    Published
    24 May 2022
    GHSA-g7xc-m762-wg8f
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions

    Published
    24 May 2022
    GHSA-mj8w-h522-jwm8
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs

    Published
    24 May 2022
    GHSA-4rjr-3gj2-5crq
    Fix available
    Packages

    mongodb

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in MongoDB Rust Driver

    Published
    24 May 2022
    GHSA-6j4j-22qg-9ffm
    Fix available
    Packages

    nukeviet/nukeviet

    Summary

    NukeViet Cross-site Scripting via the editor in the News module

    Published
    24 May 2022
    GHSA-84gf-rw24-pfqg
    Fix available
    Packages

    nukeviet/nukeviet

    Summary

    NukeViet SQL Injection vulnerability via topicsid parameter

    Published
    24 May 2022
    GHSA-m8jx-mxf9-2rpw
    Fix available
    Packages

    nukeviet/nukeviet, nukeviet/nukeviet, nukeviet/nukeviet, nukeviet/nukeviet

    Summary

    NukeViet SQL Injection vulnerability

    Published
    24 May 2022
    GHSA-2w4h-f44w-968f
    Fix available
    Packages

    org.neo4j:neo4j-kernel

    Summary

    Improper Privilege Management in Neo4j Graph Database

    Published
    24 May 2022
    GHSA-q394-h7f5-7f44
    Fix available
    Packages

    org.elasticsearch.client:elasticsearch-rest-client

    Summary

    Generation of Error Message Containing Sensitive Information in Elasticsearch

    Published
    24 May 2022
    GHSA-842m-vp3r-qwwr
    Fix available
    Packages

    thinkcmf/thinkcmf

    Summary

    ThinkCMF Cross Site Request Forgerly (CSRF) vulnerability

    Published
    24 May 2022
    GHSA-grvm-gcqf-gh8q
    No fix available
    Packages

    xo-web, xo-server

    Summary

    Xen Orchestra Mishandles Authorization

    Published
    24 May 2022
    GHSA-254j-mmc5-qhpx
    Fix available
    Packages

    smashing

    Summary

    Smashing Cross-site Scripting vulnerability

    Published
    24 May 2022
    GHSA-3cfg-rxh6-h2rh
    No fix available
    Packages

    lavalite/cms

    Summary

    LavaLite Stored Cross-site Scripting vulnerability

    Published
    24 May 2022
    GHSA-gjf5-j475-p4g6
    No fix available
    Packages

    lavalite/cms

    Summary

    Stored XSS in LavaLite 5.8.0

    Published
    24 May 2022
    GHSA-vv33-27jm-cvxq
    Fix available
    Packages

    lavalite/cms

    Summary

    Stored XSS in LavaLite 5.8.0

    Published
    24 May 2022
    GHSA-qfhw-fv3g-v836
    No fix available
    Packages

    plone

    Summary

    Plone has stored XSS in folder contents

    Published
    24 May 2022
    GHSA-4wr9-2xc6-jmg5
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Session fixation vulnerability in Jenkins

    Published
    24 May 2022