Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-4pmp-38hf-rmwj
    Fix available
    Packages

    neutron, neutron

    Summary

    OpenStack Neutron allows remote authenticated users to cause a denial of service

    Published
    17 May 2022
    GHSA-479j-jf2p-38pg
    Fix available
    Packages

    glance

    Summary

    OpenStack Glance improper validation of the image_size_cap configuration option

    Published
    17 May 2022
    GHSA-66gr-xrcf-8jpq
    Fix available
    Packages

    drupal/core, drupal/core

    Summary

    Drupal Open Redirect

    Published
    17 May 2022
    GHSA-p745-347h-hjfw
    Fix available
    Packages

    drupal/core, drupal/core, drupal/drupal, drupal/drupal

    Summary

    Drupal sensitive information disclosure

    Published
    17 May 2022
    GHSA-j6f7-hghw-g437
    Fix available
    Packages

    bottle

    Summary

    bottle.py vulnerable to CRLF Injection

    Published
    17 May 2022
    GHSA-pvcp-73cg-6f77
    No fix available
    Packages

    web2py

    Summary

    Web2py Reflected XSS vulnerability

    Published
    17 May 2022
    GHSA-v4w5-p2hg-8fh6
    Fix available
    Packages

    urllib3

    Summary

    Urllib3 Incorrect Certificate Validation

    Published
    17 May 2022
    GHSA-jpr7-8rxm-4vgx
    Fix available
    Packages

    trytond, trytond, trytond, trytond, trytond

    Summary

    Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter

    Published
    17 May 2022
    GHSA-97gm-mcv6-cphm
    Fix available
    Packages

    com.liferay.portal:portal-impl, com.liferay.portal:portal-service

    Summary

    Shell command injection in Liferay Portal

    Published
    17 May 2022
    GHSA-gp69-xcm6-ffqj
    Fix available
    Packages

    web2py

    Summary

    Web2py Cross-Site Request Forgery vulnerability

    Published
    17 May 2022
    GHSA-ffcm-vhcw-p32r
    Fix available
    Packages

    typo3/cms

    Summary

    TYPO3 Backend component Cross-site scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-g58x-p3pj-rg52
    Fix available
    Packages

    moodle/moodle

    Summary

    Moodle Glossary search displays entries without checking user permissions to view them

    Published
    17 May 2022
    GHSA-6r76-f8c8-fh7p
    Fix available
    Packages

    moodle/moodle, moodle/moodle

    Summary

    Moodle Cross-site Scripting in assignment submission page

    Published
    17 May 2022
    GHSA-jxg5-35fj-ccwf
    Fix available
    Packages

    typo3/cms-extbase, typo3/cms-extbase, typo3/cms-extbase

    Summary

    Extbase for TYPO3 allows RCE

    Published
    17 May 2022
    GHSA-h3q4-6j7f-r24c
    Fix available
    Packages

    priority

    Summary

    priority vulnerable to denial of service

    Published
    17 May 2022
    GHSA-w799-prg3-cx77
    Fix available
    Packages

    python-jose

    Summary

    python-jose failure to use a constant time comparison for HMAC keys

    Published
    17 May 2022
    GHSA-3x76-j3jj-439j
    Fix available
    Packages

    moin

    Summary

    MoinMoin Cross-site Scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-fj26-q4vh-85f6
    Fix available
    Packages

    moin

    Summary

    MoinMoin Cross-site Scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-5fq5-pfv8-mrfv
    Fix available
    Packages

    moin

    Summary

    MoinMoin Cross-site Scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-v2rp-9cpj-pfw2
    Fix available
    Packages

    salt, salt

    Summary

    Salt Insecure configuration of PAM external authentication service

    Published
    17 May 2022
    GHSA-hvmj-356c-gpf4
    Fix available
    Packages

    salt

    Summary

    Salt allows deleted minions to read or write to minions with the same id

    Published
    17 May 2022
    GHSA-84jm-cpc5-c7g7
    Fix available
    Packages

    plone, plone

    Summary

    Plone XSS in Zope ZMI

    Published
    17 May 2022
    GHSA-x9mm-6gpf-f749
    Fix available
    Packages

    org.apache.poi:poi

    Summary

    Loop with Unreachable Exit Condition in Apache POI

    Published
    17 May 2022
    GHSA-chqf-hx79-gxc6
    Fix available
    Packages

    openpyxl

    Summary

    Improper Restriction of XML External Entity Reference in Openpyxl

    Published
    17 May 2022
    GHSA-f9q6-69fh-4w5w
    Fix available
    Packages

    flask-oidc

    Summary

    flask-oidc Open Redirect vulnerability

    Published
    17 May 2022
    GHSA-8vx9-hcvq-gfv8
    Fix available
    Packages

    mantisbt/mantisbt, mantisbt/mantisbt

    Summary

    MantisBT XSS through weak CSP when using Gravatar plugin

    Published
    17 May 2022
    GHSA-v9v9-xffq-rwr4
    Fix available
    Packages

    html5lib

    Summary

    Improper Neutralization of Input During Web Page Generation in html5lib

    Published
    17 May 2022
    GHSA-8f6m-gfq9-g33v
    Fix available
    Packages

    html5lib

    Summary

    Cross-site Scripting in html5lib

    Published
    17 May 2022
    GHSA-qj6h-m7xc-r2v3
    Fix available
    Packages

    froxlor/froxlor

    Summary

    Froxlor guessable password reset token

    Published
    17 May 2022
    GHSA-v4vj-49m5-wjhw
    Fix available
    Packages

    plone, plone

    Summary

    Plone vulnerable to unauthorized disclosure of site content

    Published
    17 May 2022
    GHSA-qqgj-22gr-73vx
    Fix available
    Packages

    plone, plone, plone

    Summary

    Plone vulnerable to privilege escalation in WebDAV

    Published
    17 May 2022
    GHSA-xgjx-96v4-mqxx
    Fix available
    Packages

    org.jenkins-ci.plugins:script-security

    Summary

    Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox Protection

    Published
    17 May 2022
    GHSA-6h8x-73fx-q2h9
    No fix available
    Packages

    plone, plone

    Summary

    Chameleon in Plone allows Authentication Bypass

    Published
    17 May 2022
    GHSA-hq38-v658-g3wp
    No fix available
    Packages

    movim/moxl

    Summary

    XMPP Clients User Impersonation Vulnerability in Movim Moxl

    Published
    17 May 2022
    GHSA-6prw-8xhm-h247
    Fix available
    Packages

    salt

    Summary

    Salt uses weak permissions on the cache data

    Published
    17 May 2022
    GHSA-x34j-wxq8-7vcm
    Fix available
    Packages

    Umbraco.CMS

    Summary

    Umbraco CMS vulnerable to CSRF

    Published
    17 May 2022
    GHSA-5f6p-4hxq-rjxm
    Fix available
    Packages

    Umbraco.CMS

    Summary

    Umbraco CMS vulnerable to CSRF

    Published
    17 May 2022
    GHSA-m269-wj6g-c459
    Fix available
    Packages

    pysaml2

    Summary

    PySAML2 XML external entity attack

    Published
    17 May 2022
    GHSA-rxfp-8jmr-xc95
    No fix available
    Packages

    gethue

    Summary

    Cloudera HUE Account Enumeration

    Published
    17 May 2022
    GHSA-4wc5-gfgh-4vjx
    No fix available
    Packages

    epiceditor

    Summary

    EpicEditor XSS Vulnerability

    Published
    17 May 2022
    GHSA-2pcj-76hj-xqhm
    Fix available
    Packages

    bcit-ci/codeigniter

    Summary

    CodeIgniter arbitrary code execution

    Published
    17 May 2022
    GHSA-j24g-gm76-j829
    Fix available
    Packages

    weblate

    Summary

    Weblate user account enumeration via reset password form

    Published
    17 May 2022
    GHSA-qmh2-h7r6-gm6q
    Fix available
    Packages

    org.apache.hadoop:hadoop-client

    Summary

    Client BlockTokens not checked in Apache Hadoop

    Published
    17 May 2022
    GHSA-pxv5-5vmp-3jj4
    Fix available
    Packages

    org.apache.hadoop:hadoop-common, org.apache.hadoop:hadoop-common

    Summary

    Improper Authentication in Apache Hadoop

    Published
    17 May 2022
    GHSA-c6f9-4pmv-m7m6
    Fix available
    Packages

    org.apache.hadoop:hadoop-main, org.apache.hadoop:hadoop-main

    Summary

    Apache Hadoop allows impersonation of arbitrary cluster user accounts

    Published
    17 May 2022
    GHSA-8jxq-gpmr-h4g4
    Fix available
    Packages

    imdbphp/imdbphp

    Summary

    imdbphp Cross-Site Scripting (XSS)

    Published
    17 May 2022
    GHSA-9r7g-325h-mxrm
    Fix available
    Packages

    org.apache.hadoop:hadoop-common, org.apache.hadoop:hadoop-common

    Summary

    Improper Authentication in Apache Hadoop

    Published
    17 May 2022
    GHSA-j6jq-3q8p-xgg6
    Fix available
    Packages

    security-monkey

    Summary

    Netflix Security Monkey Open Redirect vulnerability

    Published
    17 May 2022
    GHSA-q624-9634-77gh
    Fix available
    Packages

    cherrymusic

    Summary

    Cherry Music directory traversal vulnerability

    Published
    17 May 2022
    GHSA-4wcc-jv3p-prqw
    Fix available
    Packages

    cherrymusic

    Summary

    Cherry Music Cross-site Scripting (XSS) vulnerability

    Published
    17 May 2022