Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-qp4f-2w67-c8hw
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Inbound TCP Agent Protocol/3 authentication bypass in Jenkins

    Published
    24 May 2022
    GHSA-r78q-qgx6-64pp
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Memory usage graphs accessible to anyone with Overall/Read

    Published
    24 May 2022
    GHSA-w7jr-wqw6-54xc
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Non-constant time comparison of inbound TCP agent connection secret

    Published
    24 May 2022
    GHSA-f99h-h678-fgg4
    Fix available
    Packages

    com.liferay.portal:release.portal.bom

    Summary

    Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet

    Published
    24 May 2022
    GHSA-m5c3-3gvf-q8j5
    No fix available
    Packages

    dolibarr/dolibarr

    Summary

    Dolibarr Improper Restriction of Excessive Authentication Attempts

    Published
    24 May 2022
    GHSA-qvhv-pwww-53jj
    Fix available
    Packages

    typo3/cms, typo3/cms

    Summary

    Typo3 Cross-Site Scripting in Flash component (ELTS)

    Published
    24 May 2022
    GHSA-4hf3-229w-6h8r
    No fix available
    Packages

    dolibarr/dolibarr

    Summary

    Dolibarr cross-site scripting (XSS) vulnerability

    Published
    24 May 2022
    GHSA-5957-5crx-79jx
    Fix available
    Packages

    zendframework/zend-http, zendframework/zend-http, zendframework/zendframework, zendframework/zendframework, zendframework/zendframework1, zendframework/zend-http

    Summary

    Zenario CMS vulnerable to CRLF injection

    Published
    24 May 2022
    GHSA-mh2h-6j8q-x246
    Fix available
    Packages

    codecov

    Summary

    Improper Neutralization of Special Elements in Output Used by a Downstream Component in Codecov

    Published
    24 May 2022
    GHSA-82j9-wfcf-9v2h
    Fix available
    Packages

    plone, plone, plone

    Summary

    Plone Open Redirect Vulnerability

    Published
    24 May 2022
    GHSA-8mc4-2xrc-g582
    No fix available
    Packages

    plone

    Summary

    Plone cross site scripting (XSS)

    Published
    24 May 2022
    GHSA-cw58-gpgw-hwx2
    Fix available
    Packages

    plone, plone, plone

    Summary

    Plone allows weak passwords

    Published
    24 May 2022
    GHSA-hhmf-7rgg-gcw5
    No fix available
    Packages

    plone

    Summary

    Plone SQL Injection Vulnerability

    Published
    24 May 2022
    GHSA-w6g9-xccc-347h
    No fix available
    Packages

    plone, plone-app-contenttypes

    Summary

    Plone Unauthenticated Write Vulnerability

    Published
    24 May 2022
    GHSA-cjg3-q24h-9qwf
    Fix available
    Packages

    plone-restapi, plone

    Summary

    Plone Privilege Escallation

    Published
    24 May 2022
    GHSA-gqqf-8cx6-9r7h
    Fix available
    Packages

    UmbracoCMS.Core

    Summary

    Umbraco CMS vulnerable to CSRF

    Published
    24 May 2022
    GHSA-vjxc-frw4-jmh5
    Fix available
    Packages

    io.undertow:undertow-core

    Summary

    Undertow vulnerable to Uncontrolled Resource Consumption

    Published
    24 May 2022
    GHSA-j7j6-7hfx-5522
    Fix available
    Packages

    waitress

    Summary

    Duplicate Advisory: Inconsistent Interpretation of HTTP Requests in Waitress

    Published
    24 May 2022
    GHSA-7w6p-rwhg-7h3g
    Fix available
    Packages

    grin

    Summary

    Grin Insufficient Validation

    Published
    24 May 2022
    GHSA-m44r-gv6q-9j9r
    Fix available
    Packages

    papercrop

    Summary

    papercrop does not properly handle crop input

    Published
    24 May 2022
    GHSA-q53j-p6r2-g2v4
    Fix available
    Packages

    salt

    Summary

    SaltStack Salt is vulnerable to command injection

    Published
    24 May 2022
    GHSA-69q7-hww4-8pjq
    Fix available
    Packages

    phpbb/phpbb

    Summary

    phpBB allows CSRF

    Published
    24 May 2022
    GHSA-cpqc-g4r8-6hxg
    Fix available
    Packages

    phpbb/phpbb

    Summary

    phpBB Cross-Site Request Forgery (CSRF)

    Published
    24 May 2022
    GHSA-8696-836p-c8qp
    No fix available
    Packages

    org.jenkins-ci.ruby-plugins:gitlab-hook

    Summary

    Reflected XSS vulnerability in Jenkins gitlab-hook Plugin

    Published
    24 May 2022
    GHSA-h72v-652w-xv64
    Fix available
    Packages

    org.jenkins-ci.plugins:cloudbees-jenkins-advisor

    Summary

    Missing permission checks in Health Advisor by CloudBees Plugin

    Published
    24 May 2022
    GHSA-h8w6-c53g-53vv
    Fix available
    Packages

    org.jenkins-ci.plugins:sounds

    Summary

    Missing permission checks in Jenkins Sounds Plugin allow OS command execution

    Published
    24 May 2022
    GHSA-m53p-f25q-q6fg
    Fix available
    Packages

    org.jenkins-ci.plugins:robot

    Summary

    XXE vulnerability in Jenkins Robot Framework Plugin

    Published
    24 May 2022
    GHSA-x23m-8c2h-6wg7
    Fix available
    Packages

    com.redgate.plugins.redgatesqlci:redgate-sql-ci

    Summary

    Redgate SQL Change Automation Plugin stored credentials in plain text

    Published
    24 May 2022
    GHSA-x37x-3fw2-5qw2
    Fix available
    Packages

    org.jenkins-ci.plugins:sounds

    Summary

    CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution

    Published
    24 May 2022
    GHSA-6hmm-77r2-h6hr
    Fix available
    Packages

    org.jenkins-ci.plugins:ec2

    Summary

    Missing permission checks in Jenkins Amazon EC2 Plugin

    Published
    24 May 2022
    GHSA-9hvf-pfq3-7pp6
    Fix available
    Packages

    org.jenkins-ci.plugins:ec2

    Summary

    CSRF vulnerability in Jenkins Amazon EC2 Plugin

    Published
    24 May 2022
    GHSA-fc92-8r77-9297
    Fix available
    Packages

    org.jenkins-ci.plugins:cloudbees-jenkins-advisor

    Summary

    CSRF vulnerability in Health Advisor by CloudBees Plugin

    Published
    24 May 2022
    GHSA-23cv-jh4v-vffm
    Fix available
    Packages

    Microsoft.AspNetCore.All, Microsoft.AspNetCore.App, Microsoft.AspNetCore.App, Microsoft.AspNetCore.App, Microsoft.AspNetCore.Http.Connections, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86

    Summary

    Denial of service in ASP.NET Core

    Published
    24 May 2022
    GHSA-655q-9gvg-q4cm
    Fix available
    Packages

    Microsoft.AspNetCore.All, Microsoft.AspNetCore.App, Microsoft.AspNetCore.App, Microsoft.AspNetCore.App, Microsoft.AspNetCore.Http.Connections, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86

    Summary

    Remote code execution in ASP.NET Core

    Published
    24 May 2022
    GHSA-r4mw-gxf7-vxr9
    Fix available
    Packages

    Microsoft.WindowsDesktop.App.Ref, Microsoft.WindowsDesktop.App.Ref, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x64

    Summary

    Remote code execution in Microsoft.WindowsDesktop.App.Ref

    Published
    24 May 2022
    GHSA-j4fq-3fm7-wh5v
    Fix available
    Packages

    magento/core

    Summary

    Magento arbitrary PHP code execution via the productData parameter

    Published
    24 May 2022
    GHSA-m7m4-4vm8-55wg
    Fix available
    Packages

    pyamf

    Summary

    PyAMF vulnerable to XML external entity (XXE)

    Published
    24 May 2022
    GHSA-qg7x-4h4q-3m49
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    XML external entity (XXE) vulnerability in Jenkins

    Published
    24 May 2022
    GHSA-qj27-w92h-fc9r
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    XML external entity (XXE) vulnerability in Jenkins

    Published
    24 May 2022
    GHSA-p3x5-5xpx-9phm
    Fix available
    Packages

    k8s.io/ingress-nginx

    Summary

    Kubernetes ingress exposes sensitive information

    Published
    24 May 2022
    GHSA-4gjv-5jjp-rcgh
    Fix available
    Packages

    hashbrown-cms

    Summary

    HashBrown CMS RCE

    Published
    24 May 2022
    GHSA-fgj8-93xx-f6g6
    Fix available
    Packages

    phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin

    Summary

    phpMyAdmin SQL injection in user accounts page

    Published
    24 May 2022
    GHSA-cf8f-w2c5-p5jr
    Fix available
    Packages

    org.keycloak:keycloak-core

    Summary

    keycloak vulnerable to unauthorized login via mail server setup

    Published
    24 May 2022
    GHSA-g9m2-c2x5-fr2v
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle does not revoke role capabilities correctly

    Published
    24 May 2022
    GHSA-q7hx-mrv5-6mrp
    Fix available
    Packages

    hashbrown-cms

    Summary

    HashBrown CMS Directory Traversal

    Published
    24 May 2022
    GHSA-r7rm-8j6h-r933
    Fix available
    Packages

    pillow

    Summary

    Buffer Copy without Checking Size of Input in Pillow

    Published
    24 May 2022
    GHSA-4wrc-f8pq-fpqp
    Fix available
    Packages

    org.springframework:spring-web

    Summary

    Pivotal Spring Framework contains unsafe Java deserialization methods

    Published
    24 May 2022
    GHSA-2g23-qmmp-fvmr
    No fix available
    Packages

    bolt/bolt

    Summary

    Bolt Cross-site Scripting via the slug, teaser or title parameters

    Published
    24 May 2022
    GHSA-c7fv-wv9f-cgjw
    Fix available
    Packages

    mikehaertl/php-shellcommand

    Summary

    php-shellcommand command injection vulnerability

    Published
    24 May 2022
    GHSA-9hg5-7hwc-v434
    Fix available
    Packages

    com.yahoo.athenz:athenz

    Summary

    Athenz vulnerable to Open Redirect

    Published
    24 May 2022