Open Source Vulnerabilities
org.eclipse.vorto:org.eclipse.vorto.core
Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS
org.eclipse.vorto:org.eclipse.vorto.core
Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS
github.com/lxc/lxd
LXD vulnerable to Race Condition
org.openapitools:openapi-generator
OpenAPI Tools OpenAPI Generator uses HTTP in various files
org.openapitools:openapi-generator
OpenAPI Tools OpenAPI Generator uses HTTP in various files
sscms
SiteServer CMS RCE via unsafe file upload
k8s.io/kubernetes, k8s.io/kubernetes
Kubernetes did not effectively clear service account credentials
k8s.io/kubernetes/ k8s.io/kubernetes
Kubernetes did not effectively clear service account credentials
matrix-sydent
Matrix Sydent mishandles emails
org.jenkins-ci.plugins:ontrack
Sandbox bypass in ontrack Jenkins Plugin
org.jenkins-ci.plugins:ontrack
Sandbox bypass in ontrack Jenkins Plugin
com.xebialabs.deployit.ci:deployit-plugin
Missing permission check in Jenkins XebiaLabs XL Deploy Plugin
com.xebialabs.deployit.ci:deployit-plugin
Missing permission check in Jenkins XebiaLabs XL Deploy Plugin
org.jenkins-ci.plugins:gitlab-plugin
Jenkins GitLab Plugin missing permission checks
org.jenkins-ci.plugins:gitlab-plugin
Jenkins GitLab Plugin missing permission checks
org.jenkins-ci.plugins:jira-ext
Jenkins jira-ext Plugin stores credentials unencrypted
org.jenkins-ci.plugins:jira-ext
Jenkins jira-ext Plugin stores credentials unencrypted
com.xebialabs.deployit.ci:deployit-plugin
Jenkins XebiaLabs XL Deploy Plugin vulnerable to Cross-site request forgery (CSRF)
com.xebialabs.deployit.ci:deployit-plugin
Jenkins XebiaLabs XL Deploy Plugin vulnerable to Cross-site request forgery (CSRF)
org.jenkins-ci.plugins:gitlab-plugin
Jenkins GitLab Plugin Cross-Site Request Forgery vulnerability
org.jenkins-ci.plugins:gitlab-plugin
Jenkins GitLab Plugin Cross-Site Request Forgery vulnerability
org.jenkins-ci.plugins:azure-publishersettings-credentials
Jenkins Azure PublisherSettings Credentials Plugin stored credentials in plain text
org.jenkins-ci.plugins:azure-publishersettings-credentials
Jenkins Azure PublisherSettings Credentials Plugin stored credentials in plain text
tensorflow, tensorflow, tensorflow, tensorflow-cpu, tensorflow-cpu, tensorflow-cpu, tensorflow-gpu, tensorflow-gpu, tensorflow-gpu
Missing validation causes `TensorSummaryV2` to crash
tensorflow/ tensorflow/ tensorflow/ tensorflow-cpu/ tensorflow-cpu/ tensorflow-cpu/ tensorflow-gpu/ tensorflow-gpu/ tensorflow-gpu
Missing validation causes `TensorSummaryV2` to crash
webkit2gtk, webkit2gtk
webkit2gtk vulnerabilities
stdlib
Denial of service affecting P-521 and P-384 curves in crypto/elliptic
stdlib
Denial of service affecting P-521 and P-384 curves in crypto/elliptic
Reversible One-Way Hash and Use of a Broken or Risky Cryptographic Algorithm in io.github.javaezlib.JavaEZ
Reversible One-Way Hash and Use of a Broken or Risky Cryptographic Algorithm in io.github.javaezlib.JavaEZ
smarty3, smarty3, smarty3, smarty4, smarty4, smarty4
python-jwt
CVE-2022-29217 affecting package python-jwt for versions less than 2.4.0-1
python-jwt
CVE-2022-29217 affecting package python-jwt for versions less than 2.4.0-1
golang-github-tidwall-gjson, golang-github-tidwall-gjson, telegraf, golang-github-tidwall-gjson
golang-github-tidwall-gjson/ golang-github-tidwall-gjson/ telegraf/ golang-github-tidwall-gjson
collabtive, galette, gosa, smarty3, gosa, postfixadmin, smarty3, gosa, postfixadmin, smarty3, gosa, smarty3, postfixadmin, gosa, gosa, gosa
collabtive/ galette/ gosa/ smarty3/ gosa/ postfixadmin/ smarty3/ gosa/ postfixadmin/ smarty3/ gosa/ smarty3/ postfixadmin/ gosa/ gosa/ gosa
libengine-gost-openssl1.1, libengine-gost-openssl1.1, libengine-gost-openssl1.1
libengine-gost-openssl1.1/ libengine-gost-openssl1.1/ libengine-gost-openssl1.1
radare2, radare2, radare2, radare2, radare2, radare2
radare2/ radare2/ radare2/ radare2/ radare2/ radare2
Potential buffer overflow in function DFU upload in Azure RTOS USBX
Potential buffer overflow in function DFU upload in Azure RTOS USBX
Buffer Overflow on creating key transport blob in GOST Engine
Limited Authentication Bypass for Media Files in Opencast
Buffer overflow on HUB descriptor in Azure RTOS USBX
Possible information disclosure inside TreeGrid component with default data provider
Possible information disclosure inside TreeGrid component with default data provider
