Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-pr9x-qmp5-j3rr
    Fix available
    Packages

    org.apache.hadoop:hadoop-client

    Summary

    Improper Input Validation in Apache Hadoop

    Published
    13 May 2022
    GHSA-qm7f-r83w-3p46
    Fix available
    Packages

    org.apache.hadoop:hadoop-client

    Summary

    Improper Neutralization of Input During Web Page Generation in Apache Hadoop

    Published
    13 May 2022
    GHSA-v9gf-98vr-mgp2
    Fix available
    Packages

    baserproject/basercms

    Summary

    baserCMS Access Control Bypass

    Published
    13 May 2022
    GHSA-6wr6-54mw-mvhr
    Fix available
    Packages

    baserproject/basercms

    Summary

    BaserCMS privilege escallation

    Published
    13 May 2022
    GHSA-3g2p-7c6p-vj8c
    Fix available
    Packages

    qpid-python

    Summary

    Apache Qpid Python client Improper certificate validation

    Published
    13 May 2022
    GHSA-2mvg-c6mg-3q63
    No fix available
    Packages

    concrete5/concrete5

    Summary

    Concrete CMS vulnerable to cross-site scripting (XSS)

    Published
    13 May 2022
    GHSA-wq4c-wm6x-jw44
    No fix available
    Packages

    node-inspector

    Summary

    Withdrawn Advisory: Node.js Inspector RCE via DNS Rebinding

    Published
    13 May 2022
    GHSA-7cwj-j333-x7f7
    Fix available
    Packages

    org.apache.zookeeper:zookeeper, org.apache.zookeeper:zookeeper

    Summary

    Uncontrolled Resource Consumption in Apache ZooKeeper

    Published
    13 May 2022
    GHSA-5fh8-x9xc-hxmc
    Fix available
    Packages

    irisnet-crypto

    Summary

    irisnet-crypto RCE Vulnerability

    Published
    13 May 2022
    GHSA-jrqm-v8cv-53ww
    Fix available
    Packages

    matrix-synapse

    Summary

    Matrix Synapse Predictable Secret Key

    Published
    13 May 2022
    GHSA-hmx6-gc2p-5p82
    Fix available
    Packages

    com.nablarch.framework:nablarch-fw-web

    Summary

    Nablarch Incomplete Cryptography

    Published
    13 May 2022
    GHSA-4q2w-rw7m-xqw6
    Fix available
    Packages

    nnabla

    Summary

    Sony Neural Network Libraries reliance on untrusted inputs prior to v1.0.10

    Published
    13 May 2022
    GHSA-j99g-qjvx-995g
    Fix available
    Packages

    contao/contao, contao/core-bundle

    Summary

    Contao Does Not Expire Tokens Correctly

    Published
    13 May 2022
    GHSA-q3cc-rr2c-87r6
    Fix available
    Packages

    hex_core

    Summary

    Hex authenticity of signed packages not validated

    Published
    13 May 2022
    GHSA-3wqf-4x89-9g79
    Fix available
    Packages

    bootstrap, bootstrap, bootstrap, bootstrap, org.webjars:bootstrap, org.webjars:bootstrap, bootstrap, bootstrap, bootstrap.sass, bootstrap-sass, twbs/bootstrap, twbs/bootstrap

    Summary

    Bootstrap vulnerable to Cross-Site Scripting (XSS)

    Published
    13 May 2022
    GHSA-5hg8-r9vq-gjqp
    Fix available
    Packages

    org.apache.xmlgraphics:fop

    Summary

    Improper Restriction of XML External Entity Reference in Apache FOP

    Published
    13 May 2022
    GHSA-3p68-m5qw-9g9w
    Fix available
    Packages

    ezyang/htmlpurifier

    Summary

    HTML Purifier cross-site scripting (XSS) vulnerability

    Published
    13 May 2022
    GHSA-2cjc-rgmp-x649
    Fix available
    Packages

    github.com/traefik/traefik

    Summary

    Traefik Missing Authentication

    Published
    13 May 2022
    GHSA-v3h8-rw48-h4gr
    Fix available
    Packages

    org.apache.geronimo:geronimo

    Summary

    Apache Geronimo Hash Collisions Cause DoS

    Published
    13 May 2022
    GHSA-5jrp-w8fr-mrww
    Fix available
    Packages

    fluentd

    Summary

    Fluentd Escape Sequence Injection Vulnerability

    Published
    13 May 2022
    GHSA-fc4h-467w-46rh
    Fix available
    Packages

    ansible, ansible, ansible

    Summary

    Ansible Arbitrary Code Execution

    Published
    13 May 2022
    GHSA-grm6-x6mr-q3cv
    Fix available
    Packages

    horizon, horizon

    Summary

    OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability

    Published
    13 May 2022
    GHSA-f7cr-7c2c-fm8r
    Fix available
    Packages

    ironic, ironic

    Summary

    OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor

    Published
    13 May 2022
    GHSA-3xvg-x47j-x75w
    Fix available
    Packages

    ansible, ansible, ansible

    Summary

    Ansible Improper Input Validation vulnerability

    Published
    13 May 2022
    GHSA-9773-3fqg-8w25
    Fix available
    Packages

    neutron, neutron, neutron, neutron

    Summary

    OpenStack Neutron's unsupported dport option prevents applying security groups

    Published
    13 May 2022
    GHSA-j569-fghw-f9rx
    Fix available
    Packages

    ansible, ansible, ansible

    Summary

    Ansible sensitive information disclosure

    Published
    13 May 2022
    GHSA-jr9m-v5qh-mh2j
    Fix available
    Packages

    neutron, neutron, neutron

    Summary

    OpenStack Neutron overlapping security group rules prevents compute node network configuration

    Published
    13 May 2022
    GHSA-qcj3-h27m-mp9x
    Fix available
    Packages

    octavia, octavia

    Summary

    Openstack Octavia allows Insertion of Sensitive Information into Log File

    Published
    13 May 2022
    GHSA-53wm-97p6-582f
    No fix available
    Packages

    instack-undercloud

    Summary

    instack-undercloud vulnerable to symlink attack on tmp files

    Published
    13 May 2022
    GHSA-3m8p-xpm6-8ww3
    Fix available
    Packages

    ansible

    Summary

    Ansible Arbitrary Code Execution

    Published
    13 May 2022
    GHSA-x634-34m9-96mp
    Fix available
    Packages

    neutron, neutron, neutron

    Summary

    OpensStack Neutron Denial of Service Vulnerability

    Published
    13 May 2022
    GHSA-hvxr-2fvv-c3wq
    Fix available
    Packages

    neutron, neutron, neutron, neutron

    Summary

    OpenStack Neutron Race Condition vulnerability

    Published
    13 May 2022
    GHSA-j36m-hv43-7w7m
    Fix available
    Packages

    keystone, keystone, keystone

    Summary

    OpenStack Identity service (keystone) Incorrect Authorization

    Published
    13 May 2022
    GHSA-vq76-5ghr-9p4v
    Fix available
    Packages

    manila-ui

    Summary

    Openstack Manila Persistent XSS in Metadata field

    Published
    13 May 2022
    GHSA-4m8c-h7fr-gq5c
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry vulnerable to Cross-Site Request Forgery

    Published
    13 May 2022
    GHSA-9frw-wmvq-5rrc
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry UAA Identity Zone Admin Privilege Escalation

    Published
    13 May 2022
    GHSA-cgrg-x34r-78f3
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry UAA password reset vulnerability

    Published
    13 May 2022
    GHSA-cw9c-v3v2-99hm
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Blind SQL Injection with privileged Cloud Foundry UAA endpoints

    Published
    13 May 2022
    GHSA-jcmh-x32v-7mgf
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry UAA privilege escalation with user invitations

    Published
    13 May 2022
    GHSA-pgjc-gc7g-p2c6
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry UAA Privilege Escalation

    Published
    13 May 2022
    GHSA-fm5c-2rwc-887w
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry UAA reset password vulnerable to brute force attack

    Published
    13 May 2022
    GHSA-hxgw-7539-pv7r
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry denial of service vulnerability

    Published
    13 May 2022
    GHSA-p9qj-4rjp-j3w9
    Fix available
    Packages

    org.apache.directory.studio:org.apache.directory.studio.ldapbrowser.core

    Summary

    Apache Directory Studio Command Injection

    Published
    13 May 2022
    GHSA-xcvr-qv8h-m7xw
    Fix available
    Packages

    Microsoft.NETCore.Jit, Microsoft.NETCore.Jit, Microsoft.NETCore.Jit

    Summary

    .NET Core Denial of Service Vulnerability

    Published
    13 May 2022
    GHSA-6fxm-66hq-fc96
    Fix available
    Packages

    org.apache.commons:commons-compress

    Summary

    Uncontrolled Resource Consumption in Apache Commons Compress

    Published
    13 May 2022
    GHSA-q4q2-93pw-qwgf
    Fix available
    Packages

    io.pivotal.spring.cloud:spring-cloud-sso-connector

    Summary

    Issuer validation regression in Spring Cloud SSO Connector

    Published
    13 May 2022
    GHSA-87vg-5pgx-pggh
    Fix available
    Packages

    org.springframework.integration:spring-integration-zip

    Summary

    spring-integration-zip Arbitrary File Write

    Published
    13 May 2022
    GHSA-8v97-gv3g-32rf
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    UAA privilege escalation across identity zones

    Published
    13 May 2022
    GHSA-fj69-p8f6-q97h
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password

    Published
    13 May 2022
    GHSA-cq6m-74r4-x77g
    Fix available
    Packages

    org.cloudfoundry.identity:cloudfoundry-identity-server

    Summary

    Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password

    Published
    13 May 2022