Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-9w4v-9c99-hv7r
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server exposes sensitive information via its System Console UI

    Published
    24 May 2022
    GHSA-h3qg-w9j5-wh3m
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`

    Published
    24 May 2022
    GHSA-h8qw-xqm9-q66j
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to XSS through customizable theme color-code values

    Published
    24 May 2022
    GHSA-cffj-7w5c-jqjh
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server vulnerable to Cross-site Scripting through file preview feature

    Published
    24 May 2022
    GHSA-8v7v-6mmm-xjxm
    Fix available
    Packages

    dolibarr/dolibarr

    Summary

    Dolibarr SQL injection vulnerability in accountancy/customer/card.php

    Published
    24 May 2022
    GHSA-vwxv-frj6-fhc9
    Fix available
    Packages

    omero-web

    Summary

    OMERO-web Sensitive Data Exposure

    Published
    24 May 2022
    GHSA-4hch-r9xf-6vfr
    Fix available
    Packages

    mjml

    Summary

    MJML vulnerable to path traversal

    Published
    24 May 2022
    GHSA-x6gq-vr59-4q5q
    No fix available
    Packages

    kumbiaphp/kumbiapp

    Summary

    KumbiaPHP Cross-site Scripting

    Published
    24 May 2022
    GHSA-443j-6p7g-6v4w
    Fix available
    Packages

    mistral

    Summary

    OpenStack Mistral DoS

    Published
    24 May 2022
    GHSA-4ph4-q9r5-6wm6
    Fix available
    Packages

    org.springframework.batch:spring-batch-core

    Summary

    Deserialization of Untrusted Data in Spring Batch

    Published
    24 May 2022
    GHSA-8j5r-9687-88w5
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Fails to Sanitize API Data

    Published
    24 May 2022
    GHSA-v377-8f8f-532h
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Vulnerable to Arbitrary Code Execution

    Published
    24 May 2022
    GHSA-v3m2-pg96-w33m
    Fix available
    Packages

    cinder, cinder, cinder, os-brick, os-brick, os-brick

    Summary

    Openstack cinder Improper handling of ScaleIO backend credentials

    Published
    24 May 2022
    GHSA-g3m9-qrfj-xw4g
    Fix available
    Packages

    Microsoft.ChakraCore

    Summary

    ChakraCore RCE Vulnerability

    Published
    24 May 2022
    GHSA-p9qw-fh38-x37f
    No fix available
    Packages

    opencart/opencart

    Summary

    OpenCart Cross-site Scripting

    Published
    24 May 2022
    GHSA-4r8c-pj7x-m5jx
    Fix available
    Packages

    verbb/comments

    Summary

    Comments plugin Cross-Site Request Forgery (CSRF)

    Published
    24 May 2022
    GHSA-69ww-wv3j-mhg4
    Fix available
    Packages

    verbb/comments

    Summary

    Comments plugin stored Cross-site Scripting (XSS) via an asset volume name

    Published
    24 May 2022
    GHSA-jhhf-c849-3rh2
    Fix available
    Packages

    verbb/comments

    Summary

    Comments plugin stored Cross-site Scripting via a guest name

    Published
    24 May 2022
    GHSA-c264-8834-ppj2
    Fix available
    Packages

    org.jenkins-ci.plugins:swarm

    Summary

    CSRF vulnerability in Jenkins Swarm Plugin

    Published
    24 May 2022
    GHSA-h5mv-fv98-gqmq
    No fix available
    Packages

    org.jenkins-ci.plugins:play-autotest-plugin

    Summary

    OS command injection vulnerability in Jenkins Play Framework Plugin

    Published
    24 May 2022
    GHSA-hj32-9mcw-5cwh
    No fix available
    Packages

    hudson.plugins:project-inheritance

    Summary

    Missing permission check in Jenkins Project Inheritance Plugin

    Published
    24 May 2022
    GHSA-qmf3-w5jf-cv54
    No fix available
    Packages

    org.jenkins-ci.plugins:svn-partial-release-mgr

    Summary

    XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin

    Published
    24 May 2022
    GHSA-w53q-r5cw-6vjh
    No fix available
    Packages

    hudson.plugins:project-inheritance

    Summary

    Missing permission check in Jenkins Project Inheritance Plugin

    Published
    24 May 2022
    GHSA-j852-mp82-wv2g
    Fix available
    Packages

    org.jenkins-ci.plugins:swarm

    Summary

    Improper permission checks in Jenkins Swarm Plugin

    Published
    24 May 2022
    GHSA-q397-w28f-jx97
    Fix available
    Packages

    io.jenkins.plugins:echarts-api

    Summary

    Stored XSS vulnerability in Jenkins ECharts API Plugin

    Published
    24 May 2022
    GHSA-q87g-7mp5-765q
    Fix available
    Packages

    org.jenkins-ci.plugins:script-security

    Summary

    Improper Neutralization of Input During Web Page Generation in Jenkins Script Security Plugin

    Published
    24 May 2022
    GHSA-rp4x-xpgf-4xv7
    No fix available
    Packages

    org.jenkins-ci.plugins:selenium

    Summary

    Complete lack of CSRF protection in Jenkins Selenium Plugin can lead to OS command injection

    Published
    24 May 2022
    GHSA-x68x-wvm2-hqc8
    Fix available
    Packages

    org.jenkins-ci.plugins:compact-columns

    Summary

    Stored XSS vulnerability in Jenkins Compact Columns Plugin

    Published
    24 May 2022
    GHSA-x9rq-9h44-f84v
    Fix available
    Packages

    io.jenkins.plugins:echarts-api

    Summary

    Stored XSS vulnerability in Jenkins ECharts API Plugin

    Published
    24 May 2022
    GHSA-fx6x-h9g4-56f8
    Fix available
    Packages

    github.com/containernetworking/plugins

    Summary

    containernetworking/plugins vulnerable to MitM attacks

    Published
    24 May 2022
    GHSA-m983-q76g-cwpq
    Fix available
    Packages

    wp-premium/gravityforms

    Summary

    Gravity Forms plugin leak hashed passwords

    Published
    24 May 2022
    GHSA-mqhw-wq8p-vf5r
    Fix available
    Packages

    mediawiki/core

    Summary

    MediaWiki Open Redirect vulnerability

    Published
    24 May 2022
    GHSA-9hv8-4frf-cprf
    Fix available
    Packages

    github.com/grafana/grafana

    Summary

    Grafana XSS via a column style

    Published
    24 May 2022
    GHSA-mwxh-6j9v-45ph
    Fix available
    Packages

    bbpress/bbpress

    Summary

    bbPress unauthenticated privilege-escalation

    Published
    24 May 2022
    GHSA-74gc-hf33-5353
    Fix available
    Packages

    forkcms/forkcms

    Summary

    Fork CMS Cross-site Scripting Vulnerability

    Published
    24 May 2022
    GHSA-m69r-4h68-xq7j
    Fix available
    Packages

    verbb/knock-knock

    Summary

    Knock Knock plugin Open redirection vulnerability

    Published
    24 May 2022
    GHSA-h5qv-p378-3hhr
    Fix available
    Packages

    centreon/centreon, centreon/centreon, centreon/centreon, centreon/centreon

    Summary

    Centreon Sensitive Data Exposure vulnerability

    Published
    24 May 2022
    GHSA-p9xp-xghp-gqvp
    No fix available
    Packages

    bbpress/bbpress

    Summary

    bbPress stored Cross-Site Scripting (XSS) vulnerability in the Forum creation section

    Published
    24 May 2022
    GHSA-wxvr-qqm7-6h65
    Fix available
    Packages

    verbb/knock-knock

    Summary

    Knock Knock plugin IP Whitelist bypass via an X-Forwarded-For HTTP header

    Published
    24 May 2022
    GHSA-5v5q-3m7m-97j7
    Fix available
    Packages

    verbb/image-resizer

    Summary

    Image Resizer Cross-Site Request Forgery (CSRF)

    Published
    24 May 2022
    GHSA-p7rm-gh9g-5fr8
    Fix available
    Packages

    verbb/image-resizer

    Summary

    Image Resizer Cross-site Scripting (XSS) in the Bulk Resize action

    Published
    24 May 2022
    GHSA-7m2x-qhrq-rp8h
    Fix available
    Packages

    github.com/grafana/grafana

    Summary

    Grafana XSS via the OpenTSDB datasource

    Published
    24 May 2022
    GHSA-63h2-9cc8-fc7m
    Fix available
    Packages

    meinheld

    Summary

    meinheld vulnerable to HTTP Request Smuggling

    Published
    24 May 2022
    GHSA-3cf7-7wq6-8842
    Fix available
    Packages

    Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86

    Summary

    ASP.NET Core Denial of Service Vulnerability

    Published
    24 May 2022
    GHSA-3w5p-jhp5-c29q
    Fix available
    Packages

    Microsoft.NETCore.App, Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm64, Microsoft.NETCore.App.Runtime.linux-musl-x64, Microsoft.NETCore.App.Runtime.linux-x64, Microsoft.NETCore.App.Runtime.osx-x64, Microsoft.NETCore.App.Runtime.rhel.6-x64, Microsoft.NETCore.App.Runtime.win-arm, Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86

    Summary

    .NET Core & .NET Framework Denial of Service Vulnerability

    Published
    24 May 2022
    GHSA-9hjg-j983-mqcc
    Fix available
    Packages

    Microsoft.ChakraCore

    Summary

    ChakraCore RCE Vulnerability

    Published
    24 May 2022
    GHSA-8xv4-c7rq-j577
    Fix available
    Packages

    Microsoft.ChakraCore

    Summary

    ChakraCore Remote Code Execution Vulnerability

    Published
    24 May 2022
    GHSA-vr6v-g96p-cjc3
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle vulnerable to RCE

    Published
    24 May 2022
    GHSA-89fp-j8v7-p82h
    No fix available
    Packages

    microweber/microweber

    Summary

    Microweber allows Unrestricted File Upload

    Published
    24 May 2022
    GHSA-fvf9-2hjp-w936
    No fix available
    Packages

    dolibarr/dolibarr

    Summary

    Dolibarr Stored Cross-site Scripting via file upload

    Published
    24 May 2022