Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-wwwh-47wp-m522
    Fix available
    Packages

    ansible

    Summary

    Ansible Sandbox Escape via Symlink Attack

    Published
    13 May 2022
    GHSA-3g56-2hh3-35ph
    Fix available
    Packages

    sosreport

    Summary

    SoSReport Predictable Tmp File Names

    Published
    13 May 2022
    GHSA-7vpq-g998-qpv7
    Fix available
    Packages

    io.netty:netty, io.netty:netty, io.netty:netty, io.netty:netty, io.netty:netty, io.netty:netty-all

    Summary

    Netty denial of service vulnerability

    Published
    13 May 2022
    GHSA-jrcv-3c5h-rh3q
    Fix available
    Packages

    sickrage

    Summary

    SiCKRAGE Discloses Plaintext Credentials

    Published
    13 May 2022
    GHSA-63qj-p8gh-5xxx
    Fix available
    Packages

    rap2hpoutre/laravel-log-viewer

    Summary

    Plaintext Storage of Sensitive Information in Laravel Log Viewer before v0.13.0

    Published
    13 May 2022
    GHSA-w3qr-8v4r-592m
    Fix available
    Packages

    Microsoft.ChakraCore

    Summary

    ChakraCore information disclosure vulnerability

    Published
    13 May 2022
    GHSA-wg47-6cqc-q52j
    Fix available
    Packages

    Microsoft.ChakraCore

    Summary

    ChakraCore Security Bypass

    Published
    13 May 2022
    GHSA-xphq-3x6q-q2qq
    Fix available
    Packages

    Microsoft.ChakraCore

    Summary

    ChakraCore information disclosure vulnerability

    Published
    13 May 2022
    GHSA-6xhj-p29v-82j8
    Fix available
    Packages

    org.apache.sentry:sentry

    Summary

    Apache Sentry may allow attacker to access/remove data from Sentry protected table

    Published
    13 May 2022
    GHSA-j2xq-pfff-mvgg
    Fix available
    Packages

    org.apache.pdfbox:pdfbox, org.apache.pdfbox:pdfbox

    Summary

    Loop with Unreachable Exit Condition in Apache PDFBox

    Published
    13 May 2022
    GHSA-52gq-7j6c-xw6x
    Fix available
    Packages

    org.apache.cassandra:cassandra-all

    Summary

    Missing Authentication for Critical Function in Apache Cassandra

    Published
    13 May 2022
    GHSA-923w-2xv2-7pr8
    Fix available
    Packages

    simplesamlphp/saml2, simplesamlphp/saml2, simplesamlphp/saml2

    Summary

    SimpleSAMLphp Improper Verification of Cryptographic Signature

    Published
    13 May 2022
    GHSA-ph34-pc88-72gc
    Fix available
    Packages

    npm

    Summary

    Incorrect Permission Assignment for Critical Resource in NPM

    Published
    13 May 2022
    GHSA-mvmv-rq2j-97p2
    Fix available
    Packages

    ep_etherpad-lite

    Summary

    Etherpad Lite Access Restriction Bypass

    Published
    13 May 2022
    GHSA-qv5p-6wrc-79wg
    Fix available
    Packages

    simplesamlphp/simplesamlphp

    Summary

    SimpleSAMLphp Use of insecure connection charset (sqlauth module)

    Published
    13 May 2022
    GHSA-4vrv-ch96-6h42
    Fix available
    Packages

    mysql:mysql-connector-java

    Summary

    Improper Privilege Management in MySQL Connectors Java

    Published
    13 May 2022
    GHSA-j7fx-v37j-v3w7
    No fix available
    Packages

    craftcms/cms

    Summary

    Craft CMS Vulnerable to Server-Side Template Injection

    Published
    13 May 2022
    GHSA-r2jf-rc5v-vmpv
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Incorrect Authorization in Jenkins

    Published
    13 May 2022
    GHSA-2632-h32j-6rg9
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Missing Release of Resource after Effective Lifetime in Jenkins

    Published
    13 May 2022
    GHSA-8qpf-fv36-h4r8
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core

    Summary

    Infinite Loop in Jenkins Core

    Published
    13 May 2022
    GHSA-8vg7-gh73-866v
    Fix available
    Packages

    org.jenkins-ci.plugins:accurev

    Summary

    Jenkins Accurev Plugin CSRF vulnerability and missing permission checks

    Published
    13 May 2022
    GHSA-fjh2-qhfh-rvfc
    Fix available
    Packages

    org.jenkins-ci.plugins:maven-artifact-choicelistprovider

    Summary

    Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin CSRF vulnerability and missing permission checks

    Published
    13 May 2022
    GHSA-fqg2-c97r-rqcj
    Fix available
    Packages

    org.csanchez.jenkins.plugins:kubernetes

    Summary

    Exposure of Sensitive Information in Jenkins Kubernetes Plugin

    Published
    13 May 2022
    GHSA-pwrm-8mvm-p2f2
    Fix available
    Packages

    org.jenkins-ci.plugins:pangolin-testrail-connector

    Summary

    Jenkins Agiletestware Pangolin Connector for TestRail Plugin CSRF vulnerability and missing permission checks

    Published
    13 May 2022
    GHSA-wwgx-94v6-fc2p
    Fix available
    Packages

    org.jenkins-ci.plugins:ssh-agent

    Summary

    Jenkins SSH Agent Plugin exposes SSH private key password to users with permission to read the build log

    Published
    13 May 2022
    GHSA-4wgf-9x5r-p938
    No fix available
    Packages

    athlon1600/php-proxy

    Summary

    Weak Cryptography in PHP-Proxy

    Published
    13 May 2022
    GHSA-pfrc-5hhq-6hvr
    Fix available
    Packages

    showdoc/showdoc

    Summary

    Showdoc Unauthenticated Access

    Published
    13 May 2022
    GHSA-h3mr-q96r-37v4
    Fix available
    Packages

    phpbb/phpbb

    Summary

    phpBB Remote Code Execution

    Published
    13 May 2022
    GHSA-vm3q-58wm-2r2x
    Fix available
    Packages

    pg-query, pglast

    Summary

    libpg_query memory leak

    Published
    13 May 2022
    GHSA-qc9p-mjxm-j2wj
    Fix available
    Packages

    asciidoctor

    Summary

    Asciidoctor Infinite Loop vulnerability

    Published
    13 May 2022
    GHSA-7r36-jf3c-jhp4
    Fix available
    Packages

    TGServiceInterface

    Summary

    Duplicate Advisory: tgstation-server vulnerable to cached user logins in legacy server

    Published
    13 May 2022
    GHSA-hwrm-63v2-42g4
    Fix available
    Packages

    ansible, ansible, ansible

    Summary

    Ansible Leaks Data Passed to ssh-keygen

    Published
    13 May 2022
    GHSA-fmvh-rvq5-hhjx
    Fix available
    Packages

    matrix-synapse, matrix-synapse

    Summary

    Matrix Synapse Improper Signature Validation

    Published
    13 May 2022
    GHSA-mmrq-6999-72v8
    Fix available
    Packages

    openssl, openssl

    Summary

    Ruby Openssl Allows Incorrect Value Comparison

    Published
    13 May 2022
    GHSA-3x58-8qmv-wqw5
    Fix available
    Packages

    aubio

    Summary

    Aubio is vulnerable to out of bound read when samplerate > 50kHz

    Published
    13 May 2022
    GHSA-489x-ccjw-q7c4
    Fix available
    Packages

    oxid-esales/paymorrow-module, oxid-esales/paymorrow-module

    Summary

    Paymorrow Improper Input Validation vulnerability

    Published
    13 May 2022
    GHSA-wr7r-vg3c-54r5
    Fix available
    Packages

    org.apache.guacamole:guacamole-common

    Summary

    Missing Encryption of Sensitive Data in Apache Guacamole

    Published
    13 May 2022
    GHSA-4fpg-j5mp-783g
    Fix available
    Packages

    cloudtoken

    Summary

    Cloudtoken Insufficiently Protects Credentials

    Published
    13 May 2022
    GHSA-7v85-6hv2-rwgw
    Fix available
    Packages

    org.apache.jmeter:ApacheJMeter

    Summary

    Missing certificate validation in Apache JMeter

    Published
    13 May 2022
    GHSA-cx2v-jrjc-g54w
    No fix available
    Packages

    net.opentsdb:opentsdb

    Summary

    OpenTSDB vulnerable to OS Command Injection

    Published
    13 May 2022
    GHSA-j7j7-g4ww-pxg5
    Fix available
    Packages

    org.apache.jmeter:ApacheJMeter

    Summary

    Missing certificate validation in Apache JMeter

    Published
    13 May 2022
    GHSA-cv9j-7q4x-v2g2
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings may allow authenticated attacker to deny service for privileged users

    Published
    13 May 2022
    GHSA-4284-jfhc-f854
    Fix available
    Packages

    passenger

    Summary

    Phusion Passenger incorrect permission assignment

    Published
    13 May 2022
    GHSA-r6g8-mq9v-cgp4
    Fix available
    Packages

    froxlor/froxlor

    Summary

    Froxlor Incorrect Access Control

    Published
    13 May 2022
    GHSA-hr89-w7p6-pjmq
    Fix available
    Packages

    express-cart

    Summary

    express-cart allows any user to create an admin user

    Published
    13 May 2022
    GHSA-ch5v-fhg8-7gv9
    Fix available
    Packages

    matrix-synapse

    Summary

    Matrix Synapse Authorization Error

    Published
    13 May 2022
    GHSA-v8wm-g9f2-xjv4
    Fix available
    Packages

    matrix-synapse

    Summary

    Matrix Synapse Security Filtering Flaw

    Published
    13 May 2022
    GHSA-jjhj-8gx7-x836
    Fix available
    Packages

    passenger

    Summary

    Incorrect Access Control in Phusion Passenger

    Published
    13 May 2022
    GHSA-whfx-877c-5p28
    Fix available
    Packages

    passenger

    Summary

    Insecure Permissions in Phusion Passenger

    Published
    13 May 2022
    GHSA-xhfw-wjjc-4j5h
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle Cross-site Scripting

    Published
    13 May 2022