Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-j6m4-frxh-p4x8
    Fix available
    Packages

    zodb3

    Summary

    Zope Object Database Denial of Service vulnerability

    Published
    17 May 2022
    GHSA-gmc7-jvv7-w245
    Fix available
    Packages

    phpmyadmin/phpmyadmin

    Summary

    phpMyAdmin allows remote attackers to bypass authentication and obtain sensitive information

    Published
    17 May 2022
    GHSA-9645-6g72-2pv8
    Fix available
    Packages

    phpmyadmin/phpmyadmin

    Summary

    phpMyAdmin unsafely handles temporary files

    Published
    17 May 2022
    GHSA-69vw-jfq7-935g
    Fix available
    Packages

    pywebdav

    Summary

    PyWebDAV SQL Injection vulnerability

    Published
    17 May 2022
    GHSA-5pgj-r7c6-7c7w
    Fix available
    Packages

    org.apache.struts:struts2-parent

    Summary

    Apache Struts Multiple XSS Vulnerabilities

    Published
    17 May 2022
    GHSA-cvwc-g7fw-7xrj
    Fix available
    Packages

    plone

    Summary

    Plone XSS Vulnerability

    Published
    17 May 2022
    GHSA-xwg2-qc6c-7c3q
    Fix available
    Packages

    fabric

    Summary

    Fabric vulnerable to symlink attack on tmp files

    Published
    17 May 2022
    GHSA-w3j6-8j34-q43x
    Fix available
    Packages

    apache-libcloud

    Summary

    Apache Libcloud does not verify SSL certificates for HTTPS connections

    Published
    17 May 2022
    GHSA-gw85-4gmf-m7rh
    Fix available
    Packages

    org.apache.httpcomponents:httpclient

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient

    Published
    17 May 2022
    GHSA-8w48-m6hx-rjw2
    Fix available
    Packages

    zope2, zope2

    Summary

    Zope Command Execution Vulnerability

    Published
    17 May 2022
    GHSA-pwgm-jvqv-6v8p
    Fix available
    Packages

    plone, plone, plone

    Summary

    Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable

    Published
    17 May 2022
    GHSA-pcm9-fp55-563v
    Fix available
    Packages

    com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer

    Summary

    OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled

    Published
    17 May 2022
    GHSA-hq9x-8m8j-5hmh
    Fix available
    Packages

    joomla/joomla-cms

    Summary

    Joomla! vulnerable to Cross-site Scripting

    Published
    17 May 2022
    GHSA-rpc6-h455-3rx5
    Fix available
    Packages

    celery, celery, celery

    Summary

    Celery local privilege escalation vulnerability

    Published
    17 May 2022
    GHSA-9wcx-326r-7j7w
    Fix available
    Packages

    org.apache.activemq:activemq-core

    Summary

    Denial of Service in Apache ActiveMQ

    Published
    17 May 2022
    GHSA-56f8-g68r-j699
    Fix available
    Packages

    org.apache.struts:struts2-core

    Summary

    Cross-site Scripting in Apache Struts

    Published
    17 May 2022
    GHSA-3jhc-wjqf-5f2c
    Fix available
    Packages

    virtualenv

    Summary

    Virtualenv Allows Symlink Attack on /tmp/

    Published
    17 May 2022
    GHSA-v6fw-xf2c-8q43
    Fix available
    Packages

    phpmyadmin/phpmyadmin

    Summary

    phpMyAdmin Open Redirect in redirector

    Published
    17 May 2022
    GHSA-rp8h-vr48-4j8p
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests

    Published
    17 May 2022
    GHSA-2h3q-v47h-f4rc
    Fix available
    Packages

    ejabberd, ejabberd

    Summary

    Ejabberd DoS via malformed stanza

    Published
    17 May 2022
    GHSA-jw86-5cjf-mv79
    No fix available
    Packages

    ezyang/htmlpurifier

    Summary

    HTML Purifier allows remote attackers to obtain sensitive information

    Published
    17 May 2022
    GHSA-r7p6-fr3x-r877
    Fix available
    Packages

    cakephp/cakephp

    Summary

    CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file

    Published
    17 May 2022
    GHSA-7h48-m3rw-vr27
    Fix available
    Packages

    spree

    Summary

    Spree does not properly restrict the use of a hash to provide values for a model's attributes

    Published
    17 May 2022
    GHSA-g466-57gh-cqfw
    Fix available
    Packages

    spree

    Summary

    Spree uses a hardcoded hash value

    Published
    17 May 2022
    GHSA-48r9-4v93-x4wh
    Fix available
    Packages

    dompdf/dompdf

    Summary

    DOMPDF Remote File Inclusion Vulnerability

    Published
    17 May 2022
    GHSA-frgf-rv99-862x
    Fix available
    Packages

    roundup

    Summary

    Roundup Cross-site Scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-w736-qv86-vq94
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    TYPO3 Remote File Disclosure vulnerability in the jumpUrl mechanism

    Published
    17 May 2022
    GHSA-342c-f869-5m44
    Fix available
    Packages

    org.apache.sling:org.apache.sling.servlets.post

    Summary

    Apache Sling POST Servlets Denial of Service Vulnerability

    Published
    17 May 2022
    GHSA-g34c-mg6m-xvxj
    Fix available
    Packages

    cobbler

    Summary

    Cobbler subject to Command Injection

    Published
    17 May 2022
    GHSA-f68m-q26r-64f6
    Fix available
    Packages

    chef

    Summary

    Chef Improper Access Control vulnerability

    Published
    17 May 2022
    GHSA-cm54-3vvf-f5p8
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova Arbitrary file injection/corruption through directory traversal issues

    Published
    17 May 2022
    GHSA-m454-cm7h-rqhh
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova Directory traversal vulnerability

    Published
    17 May 2022
    GHSA-q7v2-w38r-pv7v
    Fix available
    Packages

    phpmyadmin/phpmyadmin

    Summary

    phpMyAdmin Multiple XSS Vulnerabilities

    Published
    17 May 2022
    GHSA-xxgm-qpj5-4886
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova Scheduler denial of service through scheduler_hints

    Published
    17 May 2022
    GHSA-vfcg-5ggc-3rxx
    No fix available
    Packages

    elixir

    Summary

    Elixir can leak information due to weak use of crypto

    Published
    17 May 2022
    GHSA-2qr7-8fp8-4xxr
    Fix available
    Packages

    com.caucho:resin

    Summary

    Caucho Quercus, as distributed in Resin, does not properly implement the `==` operator for comparisons

    Published
    17 May 2022
    GHSA-g5fx-ccwv-5c4f
    Fix available
    Packages

    com.caucho:resin

    Summary

    Caucho Quercus, as distributed in Resin, overwrites entries in SERVER superglobal array on basis of POST parameters

    Published
    17 May 2022
    GHSA-p332-fw36-4hqx
    Fix available
    Packages

    com.caucho:resin

    Summary

    Caucho Quercus, as distributed in Resin, does not properly handle unspecified characters in the names of variables

    Published
    17 May 2022
    GHSA-f7fv-v9rh-prvc
    Fix available
    Packages

    tornado

    Summary

    Tornado CRLF injection vulnerability

    Published
    17 May 2022
    GHSA-7wwr-p84q-qr3q
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Backend XSS Vulnerabilities

    Published
    17 May 2022
    GHSA-q68v-vcjg-r3vp
    No fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    TYPO3 allows remote attackers to obtain the database name via a direct request

    Published
    17 May 2022
    GHSA-w3v6-r62r-fvqh
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 API XSS Vulnerabilities

    Published
    17 May 2022
    GHSA-7jfm-px59-99w8
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Extbase Framework Unsafe Deserialization

    Published
    17 May 2022
    GHSA-xp97-6w7r-4cjc
    Fix available
    Packages

    keystone

    Summary

    OpenStack Keystone token expiration issues

    Published
    17 May 2022
    GHSA-gf2q-j2qq-pjf2
    Fix available
    Packages

    keystone

    Summary

    OpenStack Keystone Allows Remote User Account Creation

    Published
    17 May 2022
    GHSA-39vm-p9mr-4r27
    Fix available
    Packages

    beaker

    Summary

    Beaker Sensitive Information Disclosure vulnerability

    Published
    17 May 2022
    GHSA-v358-rvxr-wffx
    Fix available
    Packages

    silverstripe/framework, silverstripe/framework

    Summary

    Silverstripe XSS Vulnerabilities

    Published
    17 May 2022
    GHSA-gv6c-59h4-9pmg
    Fix available
    Packages

    silverstripe/cms

    Summary

    Silverstripe CMS Arbitrary Code Execution

    Published
    17 May 2022
    GHSA-fr34-mx6j-vpxh
    Fix available
    Packages

    impresspages/impresspages

    Summary

    ImpressPages CMS eval injection vulnerability

    Published
    17 May 2022
    GHSA-h86w-m5rm-xr33
    Fix available
    Packages

    org.postgresql:postgresql

    Summary

    Unescaped parameters in the PostgreSQL JDBC driver

    Published
    17 May 2022