Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-j984-q4qc-6qxf
    Fix available
    Packages

    librsvg

    Summary

    librsvg DoS via Cyclic References

    Published
    17 May 2022
    GHSA-cfj3-7x9c-4p3h
    Fix available
    Packages

    requests

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in Requests

    Published
    17 May 2022
    GHSA-2ch8-f849-pjg3
    Fix available
    Packages

    ajenti

    Summary

    Eugene Pankov Ajenti Cross-site scripting Vulnerabilities

    Published
    17 May 2022
    GHSA-vxhj-3x7p-jxp5
    Fix available
    Packages

    org.jboss.resteasy:resteasy-client, org.jboss.resteasy:resteasy-client

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy

    Published
    17 May 2022
    GHSA-52j9-v3jc-9xgc
    Fix available
    Packages

    trytond, trytond, trytond, trytond, trytond

    Summary

    Tryton allows users to read the hashed password

    Published
    17 May 2022
    GHSA-87r7-q54j-f9qg
    Fix available
    Packages

    murano, murano-dashboard, murano-dashboard, python-muranoclient, python-muranoclient

    Summary

    OpenStack Murano Code Execution

    Published
    17 May 2022
    GHSA-9fc7-rhq3-wm7x
    Fix available
    Packages

    org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav

    Summary

    Apache Jackrabbit Authentication Hijacking Vulnerability

    Published
    17 May 2022
    GHSA-6g9h-6v79-w4pc
    Fix available
    Packages

    drupal/drupal, drupal/core

    Summary

    Drupal Users without "Administer comments" can set comment visibility on nodes they can edit

    Published
    17 May 2022
    GHSA-vhg8-x858-7wq6
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Cross-site scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-fmqh-2j2x-vgp3
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Unprivileged access to config export

    Published
    17 May 2022
    GHSA-v6c7-8qx5-8gmp
    Fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Deserialization of Untrusted Data in Apache Tomcat

    Published
    17 May 2022
    GHSA-rp9p-863f-9c4h
    Fix available
    Packages

    org.apache.activemq:activemq-core

    Summary

    Cross-site Scripting in Apache ActiveMQ

    Published
    17 May 2022
    GHSA-34fp-xvxp-rg22
    Fix available
    Packages

    org.apache.activemq:apache-activemq, org.apache.activemq:activemq-web-demo

    Summary

    Apache ActiveMQ default configuration subject to denial of service

    Published
    17 May 2022
    GHSA-c9gx-27hq-wcvj
    Fix available
    Packages

    org.apache.activemq:activemq-core

    Summary

    Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet

    Published
    17 May 2022
    GHSA-rv8h-p43r-4x5r
    Fix available
    Packages

    oauth2

    Summary

    SimpleGeo python-oauth2 vulnerable to the use of Insufficiently Random Values to generate nonces

    Published
    17 May 2022
    GHSA-4433-4cxq-vv73
    No fix available
    Packages

    oauth2

    Summary

    SimpleGeo python-oauth2 does not check the nonce allowing replay attacks

    Published
    17 May 2022
    GHSA-5qp6-78pr-gv8c
    Fix available
    Packages

    openid/php-openid, typo3/cms

    Summary

    PHP OpenID Library Denial of Service vulnerability

    Published
    17 May 2022
    GHSA-p358-58jj-hp65
    Fix available
    Packages

    org.apache.activemq:activemq-client

    Summary

    Improper Authentication in Apache ActiveMQ

    Published
    17 May 2022
    GHSA-f9q5-46qg-74x4
    Fix available
    Packages

    pywbem

    Summary

    PyWBEM TOCTOU vulnerability in certificate validation

    Published
    17 May 2022
    GHSA-gh2c-6m38-c78j
    Fix available
    Packages

    pywbem

    Summary

    PyWBEM TOCTOU vulnerability in certificate validation

    Published
    17 May 2022
    GHSA-4rpv-g4gq-rh4m
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms, typo3/cms

    Summary

    TYPO3 vulnerable to Information Disclosure via Content Editing Wizards component

    Published
    17 May 2022
    GHSA-hqw5-62gp-rqgm
    Fix available
    Packages

    org.directwebremoting:dwr, org.directwebremoting:dwr

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in Direct Web Remoting

    Published
    17 May 2022
    GHSA-v6xv-rmqc-wcc8
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Open Redirect In Frontend Rendering

    Published
    17 May 2022
    GHSA-7f2c-vp52-gmfw
    Fix available
    Packages

    keystonemiddleware, keystonemiddleware, python-keystoneclient, python-keystoneclient

    Summary

    OpenStack keystonemiddleware does not verify certificate

    Published
    17 May 2022
    GHSA-g48f-ff5h-5f64
    Fix available
    Packages

    org.apache.hadoop:hadoop-common

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop

    Published
    17 May 2022
    GHSA-gvjg-r9fv-7qx9
    Fix available
    Packages

    glance, glance

    Summary

    OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service

    Published
    17 May 2022
    GHSA-q73f-vjc2-3gqf
    Fix available
    Packages

    glance

    Summary

    OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file

    Published
    17 May 2022
    GHSA-pw5c-xqf2-6xc2
    Fix available
    Packages

    doctrine/annotations, doctrine/cache, doctrine/common, doctrine/common, doctrine/orm, doctrine/mongodb-odm, doctrine/mongodb-odm-bundle, zendframework/zendframework1, zendframework/zend-cache, aws/aws-sdk-php, doctrine/cache, zendframework/zend-cache, zendframework/zendframework, zfcampus/zf-apigility-doctrine

    Summary

    Doctrine Security Misconfiguration Vulnerability

    Published
    17 May 2022
    GHSA-2hvh-c5c2-vj85
    Fix available
    Packages

    zendframework/zendframework1

    Summary

    Zend Framework SQL injection vector using null byte for PDO

    Published
    17 May 2022
    GHSA-5xrj-ghhp-hx7p
    Fix available
    Packages

    glance

    Summary

    OpenStack Image Service (Glance) vulnerable to Improper Access Control

    Published
    17 May 2022
    GHSA-84cw-mxhv-qvv4
    Fix available
    Packages

    radicale

    Summary

    Radicale is vulnerable to directory traversal on Windows Filesystem Storage Backend component

    Published
    17 May 2022
    GHSA-4gmg-gwjh-3mmr
    Fix available
    Packages

    phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin

    Summary

    phpMyAdmin Cryptographic Vulnerability

    Published
    17 May 2022
    GHSA-46x4-9jmv-jc8p
    Fix available
    Packages

    django

    Summary

    Django Access Restrictions Bypass

    Published
    17 May 2022
    GHSA-2j4q-9fff-236j
    Fix available
    Packages

    org.apache.struts:struts2-core

    Summary

    Apache Struts XSS Vulnerability

    Published
    17 May 2022
    GHSA-pvm9-288c-v5wq
    Fix available
    Packages

    org.apache.struts:struts2-core, org.apache.struts:struts2-core, org.apache.struts:struts2-core

    Summary

    Remote Code Execution in Apache Struts

    Published
    17 May 2022
    GHSA-383p-xqxx-rrmp
    Fix available
    Packages

    org.apache.struts:struts2-core, ognl:ognl

    Summary

    Denial of service in Apache Struts

    Published
    17 May 2022
    GHSA-f82m-w3p3-cgp3
    Fix available
    Packages

    keystone

    Summary

    OpenStack Identity Keystone Improper Access Control

    Published
    17 May 2022
    GHSA-9pp3-cvmq-9p22
    Fix available
    Packages

    neutron, neutron

    Summary

    OpenStack Neutron Intended MAC-spoofing protection mechanism bypass

    Published
    17 May 2022
    GHSA-rfxx-gxwc-923c
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Views can allow unauthorized users to see Statistics information

    Published
    17 May 2022
    GHSA-frqf-9qr4-6vxf
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Saving user accounts can sometimes grant the user all roles

    Published
    17 May 2022
    GHSA-wg33-x934-3ghh
    Fix available
    Packages

    jwcrypto

    Summary

    jwcrypto lacks the Random Filling protection mechanism

    Published
    17 May 2022
    GHSA-jpj8-49hr-wcwv
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Denial of service via transliterate mechanism

    Published
    17 May 2022
    GHSA-58fm-v4pr-jh8p
    No fix available
    Packages

    moodle/moodle

    Summary

    Moodle Unrestricted file upload vulnerability

    Published
    17 May 2022
    GHSA-7ghm-fp7p-qvjq
    No fix available
    Packages

    moodle/moodle

    Summary

    Moodle XSS Vulnerability

    Published
    17 May 2022
    GHSA-98w5-wqp9-w466
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Incorrect cache context on password reset page

    Published
    17 May 2022
    GHSA-78fq-w796-q537
    Fix available
    Packages

    org.opensaml:opensaml, edu.internet2.middleware:shibboleth-identityprovider

    Summary

    Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML

    Published
    17 May 2022
    GHSA-7q56-mp4c-gggg
    Fix available
    Packages

    org.apache.hadoop:hadoop-common, org.apache.hadoop:hadoop-common

    Summary

    Improper Access Control in Apache Hadoop

    Published
    17 May 2022
    GHSA-277w-qpxr-2549
    Fix available
    Packages

    mediaelement, contao-components/mediaelement, contao/core

    Summary

    MediaElement Vulnerable to Reflected XSS

    Published
    17 May 2022
    GHSA-74mf-vjpg-9xh7
    Fix available
    Packages

    slim/slim

    Summary

    Slim vulnerable to PHP object injection

    Published
    17 May 2022
    GHSA-6565-fg86-6jcx
    Fix available
    Packages

    django, django

    Summary

    Django Cross-site Scripting Vulnerability

    Published
    17 May 2022