Open Source Vulnerabilities
chromium
chromedriver-152.0.7977.82-1.1 on GA media
valkey, valkey-devel
Important: valkey security, bug fix, and enhancement update
valkey/ valkey-devel
Important: valkey security, bug fix, and enhancement update
389-ds-base, 389-ds-base-devel, 389-ds-base-libs, 389-ds-base-snmp, python3-lib389
Critical: 389-ds-base security, bug fix, and enhancement update
389-ds-base/ 389-ds-base-devel/ 389-ds-base-libs/ 389-ds-base-snmp/ python3-lib389
Critical: 389-ds-base security, bug fix, and enhancement update
knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions
knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions
knowns before 0.30.0 Unauthenticated Management API Exposure
knowns before 0.30.0 Path Traversal via Import Name
knowns before 0.30.0 Path Traversal via code.replace MCP action
knowns before 0.30.0 Path Traversal via code.replace MCP action
knowns before 0.30.0 Arbitrary Code Execution via LSP Binary
knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint
knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint
knowns before 0.30.0 Path Traversal via templateFile parameter
knowns before 0.30.0 Path Traversal via templateFile parameter
knowns before 0.30.0 Path Traversal via MCP doc and memory tools
knowns before 0.30.0 Path Traversal via MCP doc and memory tools
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
igniter,
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
igniter/
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
ash_lua,
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
ash_lua/
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_double_entry,
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_double_entry/
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server,
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server/
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server,
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server/
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server,
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server/
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server,
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server/
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
org.springframework.integration:spring-integration, org.springframework.integration:spring-integration-amqp, org.springframework.integration:spring-integration-bom, org.springframework.integration:spring-integration-core, org.springframework.integration:spring-integration-event, org.springframework.integration:spring-integration-feed, org.springframework.integration:spring-integration-file, org.springframework.integration:spring-integration-ftp, org.springframework.integration:spring-integration-gemfire, org.springframework.integration:spring-integration-groovy, org.springframework.integration:spring-integration-http, org.springframework.integration:spring-integration-ip, org.springframework.integration:spring-integration-jdbc, org.springframework.integration:spring-integration-jms, org.springframework.integration:spring-integration-jmx, org.springframework.integration:spring-integration-jpa, org.springframework.integration:spring-integration-kafka, org.springframework.integration:spring-integration-mail, org.springframework.integration:spring-integration-mongodb, org.springframework.integration:spring-integration-mqtt, org.springframework.integration:spring-integration-r2dbc, org.springframework.integration:spring-integration-redis, org.springframework.integration:spring-integration-rmi, org.springframework.integration:spring-integration-rsocket, org.springframework.integration:spring-integration-scripting, org.springframework.integration:spring-integration-security, org.springframework.integration:spring-integration-sftp, org.springframework.integration:spring-integration-stomp, org.springframework.integration:spring-integration-stream, org.springframework.integration:spring-integration-syslog, org.springframework.integration:spring-integration-test, org.springframework.integration:spring-integration-test-support, org.springframework.integration:spring-integration-webflux, org.springframework.integration:spring-integration-websocket, org.springframework.integration:spring-integration-ws, org.springframework.integration:spring-integration-xml, org.springframework.integration:spring-integration-xmpp, org.springframework.integration:spring-integration-zeromq, org.springframework.integration:spring-integration-zookeeper
TuxCare security update for org.springframework.integration (5 CVEs)
org.springframework.integration:spring-integration/ org.springframework.integration:spring-integration-amqp/ org.springframework.integration:spring-integration-bom/ org.springframework.integration:spring-integration-core/ org.springframework.integration:spring-integration-event/ org.springframework.integration:spring-integration-feed/ org.springframework.integration:spring-integration-file/ org.springframework.integration:spring-integration-ftp/ org.springframework.integration:spring-integration-gemfire/ org.springframework.integration:spring-integration-groovy/ org.springframework.integration:spring-integration-http/ org.springframework.integration:spring-integration-ip/ org.springframework.integration:spring-integration-jdbc/ org.springframework.integration:spring-integration-jms/ org.springframework.integration:spring-integration-jmx/ org.springframework.integration:spring-integration-jpa/ org.springframework.integration:spring-integration-kafka/ org.springframework.integration:spring-integration-mail/ org.springframework.integration:spring-integration-mongodb/ org.springframework.integration:spring-integration-mqtt/ org.springframework.integration:spring-integration-r2dbc/ org.springframework.integration:spring-integration-redis/ org.springframework.integration:spring-integration-rmi/ org.springframework.integration:spring-integration-rsocket/ org.springframework.integration:spring-integration-scripting/ org.springframework.integration:spring-integration-security/ org.springframework.integration:spring-integration-sftp/ org.springframework.integration:spring-integration-stomp/ org.springframework.integration:spring-integration-stream/ org.springframework.integration:spring-integration-syslog/ org.springframework.integration:spring-integration-test/ org.springframework.integration:spring-integration-test-support/ org.springframework.integration:spring-integration-webflux/ org.springframework.integration:spring-integration-websocket/ org.springframework.integration:spring-integration-ws/ org.springframework.integration:spring-integration-xml/ org.springframework.integration:spring-integration-xmpp/ org.springframework.integration:spring-integration-zeromq/ org.springframework.integration:spring-integration-zookeeper
TuxCare security update for org.springframework.integration (5 CVEs)
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server,
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server/
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
ash_authentication_oauth2_server,
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
ash_authentication_oauth2_server/
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload
Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload
Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints
Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints
org.springframework:spring, org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-r2dbc, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (8 CVEs)
org.springframework:spring/ org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-r2dbc/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (8 CVEs)
@vitejs/plugin-legacy, @vitejs/plugin-react, create-vite, vite
TuxCare security update for 4 packages (1 CVE)
@vitejs/plugin-legacy/ @vitejs/plugin-react/ create-vite/ vite
TuxCare security update for 4 packages (1 CVE)
org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (8 CVEs)
org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (8 CVEs)
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
libprotocol-http2-perl, libprotocol-http2-perl, libprotocol-http2-perl
libprotocol-http2-perl/ libprotocol-http2-perl/ libprotocol-http2-perl
jquery-mobile
TuxCare security update for jquery-mobile (2 CVEs)
jquery-mobile
TuxCare security update for jquery-mobile (2 CVEs)
org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (11 CVEs)
org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (11 CVEs)
exiv2
Updated exiv2 package fixes security vulnerabilities
