Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-q4v9-qjmw-j7vf
    Fix available
    Packages

    org.springframework.webflow:spring-webflow

    Summary

    Insecure Default Initialization of Resource in Pivotal Spring Web Flow

    Published
    13 May 2022
    GHSA-g283-88v5-rmq2
    Fix available
    Packages

    salt

    Summary

    SaltStack Salt allows compromised salt-minions to impersonate the salt-master

    Published
    13 May 2022
    GHSA-g3vq-f35v-vhgm
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings vulnerable to Uncontrolled Resource Consumption

    Published
    13 May 2022
    GHSA-xhj7-jr45-5w8r
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings updates user password in insecure manner

    Published
    13 May 2022
    GHSA-x869-784m-jmj2
    Fix available
    Packages

    org.apache.mesos:mesos, org.apache.mesos:mesos, org.apache.mesos:mesos

    Summary

    Denial of service in Apache Mesos

    Published
    13 May 2022
    GHSA-2c3p-9j5f-33g3
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings responds to insecure HTTP methods

    Published
    13 May 2022
    GHSA-2q65-xxg6-3qh5
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings vulnerable to parameter manipulation attacks

    Published
    13 May 2022
    GHSA-cqm6-hrgq-6869
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings has Inadequate Encryption Strength

    Published
    13 May 2022
    GHSA-q52r-g8jf-wv3x
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings allows flash content to be loaded from untrusted domains

    Published
    13 May 2022
    GHSA-57q5-x8jf-g7h8
    Fix available
    Packages

    org.jboss.resteasy:resteasy-jaxrs, org.jboss.resteasy:resteasy-jaxrs

    Summary

    Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP

    Published
    13 May 2022
    GHSA-9x63-m3cc-qf3g
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle Unauthorized searching of arbitrary blogs by typing full url

    Published
    13 May 2022
    GHSA-jjhx-5jff-rc8m
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle Improper Privilege Management

    Published
    13 May 2022
    GHSA-m34m-fgh4-v7cx
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle External blog editing takeover

    Published
    13 May 2022
    GHSA-6hpj-9xj7-2jxx
    Fix available
    Packages

    drupal/core, drupal/core, drupal/drupal, drupal/drupal

    Summary

    Drupal access control bypass vulnerability

    Published
    13 May 2022
    GHSA-7ffh-cjvg-fpr4
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Settings Tray access bypass

    Published
    13 May 2022
    GHSA-9wf6-88x4-6xvj
    Fix available
    Packages

    buddypress/buddypress

    Summary

    BuddyPress Docs plugin Improper Privilege Management

    Published
    13 May 2022
    GHSA-3327-jr93-7hq3
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal access bypass vulnerability

    Published
    13 May 2022
    GHSA-66mv-q8r2-hj8w
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal access bypass vulnerability

    Published
    13 May 2022
    GHSA-f4qx-jqfq-7785
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions

    Published
    13 May 2022
    GHSA-rhx9-3qf7-r3j7
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal Remote code execution

    Published
    13 May 2022
    GHSA-87hc-phmj-rhgh
    No fix available
    Packages

    typo3/cms

    Summary

    TYPO3 Information Disclosure Vulnerability

    Published
    13 May 2022
    GHSA-w7qx-vwr9-2j3r
    Fix available
    Packages

    drupal/core, drupal/drupal

    Summary

    Drupal editor module incorrectly checks access to inline private files

    Published
    13 May 2022
    GHSA-6xc7-4cx8-j3xc
    Fix available
    Packages

    nova-lxd

    Summary

    OpenStack Nova-LXD bypass security restrictions

    Published
    13 May 2022
    GHSA-jmvv-524f-hj5j
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat, org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Improper Handling of Exceptional Conditions in Apache Tomcat

    Published
    13 May 2022
    GHSA-9785-w233-x6hv
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Improper Resource Shutdown or Release in Apache Tomcat

    Published
    13 May 2022
    GHSA-9hg2-395j-83rm
    Fix available
    Packages

    org.apache.tomcat:tomcat-coyote, org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat.embed:tomcat-embed-core

    Summary

    Expected Behavior Violation in Apache Tomcat

    Published
    13 May 2022
    GHSA-jgj9-6v78-6g8m
    Fix available
    Packages

    org.apache.nifi:nifi, org.apache.nifi:nifi

    Summary

    Improper Authentication In Apache NiFi

    Published
    13 May 2022
    GHSA-8r7r-x48r-pf8f
    Fix available
    Packages

    salt, salt, salt

    Summary

    SaltStack Salt arbitrary command execution in Salt-api via ssh_client

    Published
    13 May 2022
    GHSA-fg9w-cffm-pmh2
    Fix available
    Packages

    org.springframework.webflow:spring-webflow

    Summary

    Insecure Default Initialization of Resource in Pivotal Spring Web Flow

    Published
    13 May 2022
    GHSA-2cf3-g243-hhfx
    No fix available
    Packages

    mysql-connector-python

    Summary

    MySQL Connectors Privilege Escalation

    Published
    13 May 2022
    GHSA-cjcf-wm2p-59h5
    Fix available
    Packages

    mysql:mysql-connector-java

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java

    Published
    13 May 2022
    GHSA-pwh7-92h3-mqr6
    Fix available
    Packages

    mysql:mysql-connector-java

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java

    Published
    13 May 2022
    GHSA-2xxh-f8r3-hvvr
    Fix available
    Packages

    mysql:mysql-connector-java

    Summary

    Improper Access Control in MySQL Connectors Java

    Published
    13 May 2022
    GHSA-5868-g58j-vrj5
    Fix available
    Packages

    phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin

    Summary

    phpMyAdmin Improper Privilege Management

    Published
    13 May 2022
    GHSA-ffmh-r67w-m88f
    Fix available
    Packages

    nova, nova

    Summary

    OpenStack Nova Denial of service attack on the compute host

    Published
    13 May 2022
    GHSA-vq76-rxx3-4r4r
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova DoS by rebuilding the same instance with a new image multiple times

    Published
    13 May 2022
    GHSA-4ccx-wjqp-5fww
    Fix available
    Packages

    librenms/librenms

    Summary

    LibreNMS Arbitrary File Read

    Published
    13 May 2022
    GHSA-92x6-h2gr-8gxq
    Fix available
    Packages

    symfony/security-csrf, symfony/security-csrf, symfony/security-csrf, symfony/security-csrf, symfony/security, symfony/security, symfony/security, symfony/security, symfony/symfony, symfony/symfony, symfony/symfony, symfony/symfony

    Summary

    Symfony CSRF Vulnerability

    Published
    13 May 2022
    GHSA-vg8g-jpm9-jh8r
    Fix available
    Packages

    pyanyapi

    Summary

    Unsafe pyyaml load usage in PyAnyAPI

    Published
    13 May 2022
    GHSA-w2wf-cgwh-vpqg
    Fix available
    Packages

    nova, nova, nova

    Summary

    OpenStack Nova Filter Scheduler Bypass

    Published
    13 May 2022
    GHSA-cwwh-4382-6fwr
    Fix available
    Packages

    dulwich

    Summary

    Dulwich RCE Vulnerability

    Published
    13 May 2022
    GHSA-8q8v-28rm-qw4w
    Fix available
    Packages

    borgbackup

    Summary

    Borg Improper Access Control vulnerability

    Published
    13 May 2022
    GHSA-xvjf-394g-phrr
    Fix available
    Packages

    nilsteampassnet/teampass

    Summary

    TeamPass Improper Privilege Management

    Published
    13 May 2022
    GHSA-5qr3-4839-88gf
    Fix available
    Packages

    nilsteampassnet/teampass

    Summary

    TeamPass Improper Privilege Management

    Published
    13 May 2022
    GHSA-7ghm-6p42-h226
    Fix available
    Packages

    nilsteampassnet/teampass

    Summary

    TeamPass Improper Privilege Management

    Published
    13 May 2022
    GHSA-2f6r-892p-69g5
    No fix available
    Packages

    genix/cms

    Summary

    GeniXCMS arbitrary PHP code execution

    Published
    13 May 2022
    GHSA-jjxg-hpm7-g95f
    No fix available
    Packages

    bzr

    Summary

    Bazaar allows remote attackers to execute arbitrary commands via a bzr+ssh URL with initial dash character in hostname

    Published
    13 May 2022
    GHSA-c6p7-vhw7-rc9w
    Fix available
    Packages

    org.onosproject:onos-base

    Summary

    ONOS vulnerable to denial of service due to unrestricted NettyMessagingManager payload

    Published
    13 May 2022
    GHSA-jfmq-4g4m-99rh
    Fix available
    Packages

    com.nimbusds:nimbus-jose-jwt

    Summary

    Nimbus JOSE+JWT vulnerable to padding oracle attack

    Published
    13 May 2022
    GHSA-597c-mh7m-48v7
    Fix available
    Packages

    simplesamlphp/simplesamlphp

    Summary

    SimpleSAMLphp Invalid token creation and validation

    Published
    13 May 2022