Open Source Vulnerabilities
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
ash_lua,
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
ash_lua/
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_double_entry,
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_double_entry/
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server,
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server/
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server,
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server/
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server,
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server/
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server,
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server/
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
org.springframework.integration:spring-integration, org.springframework.integration:spring-integration-amqp, org.springframework.integration:spring-integration-bom, org.springframework.integration:spring-integration-core, org.springframework.integration:spring-integration-event, org.springframework.integration:spring-integration-feed, org.springframework.integration:spring-integration-file, org.springframework.integration:spring-integration-ftp, org.springframework.integration:spring-integration-gemfire, org.springframework.integration:spring-integration-groovy, org.springframework.integration:spring-integration-http, org.springframework.integration:spring-integration-ip, org.springframework.integration:spring-integration-jdbc, org.springframework.integration:spring-integration-jms, org.springframework.integration:spring-integration-jmx, org.springframework.integration:spring-integration-jpa, org.springframework.integration:spring-integration-kafka, org.springframework.integration:spring-integration-mail, org.springframework.integration:spring-integration-mongodb, org.springframework.integration:spring-integration-mqtt, org.springframework.integration:spring-integration-r2dbc, org.springframework.integration:spring-integration-redis, org.springframework.integration:spring-integration-rmi, org.springframework.integration:spring-integration-rsocket, org.springframework.integration:spring-integration-scripting, org.springframework.integration:spring-integration-security, org.springframework.integration:spring-integration-sftp, org.springframework.integration:spring-integration-stomp, org.springframework.integration:spring-integration-stream, org.springframework.integration:spring-integration-syslog, org.springframework.integration:spring-integration-test, org.springframework.integration:spring-integration-test-support, org.springframework.integration:spring-integration-webflux, org.springframework.integration:spring-integration-websocket, org.springframework.integration:spring-integration-ws, org.springframework.integration:spring-integration-xml, org.springframework.integration:spring-integration-xmpp, org.springframework.integration:spring-integration-zeromq, org.springframework.integration:spring-integration-zookeeper
TuxCare security update for org.springframework.integration (5 CVEs)
org.springframework.integration:spring-integration/ org.springframework.integration:spring-integration-amqp/ org.springframework.integration:spring-integration-bom/ org.springframework.integration:spring-integration-core/ org.springframework.integration:spring-integration-event/ org.springframework.integration:spring-integration-feed/ org.springframework.integration:spring-integration-file/ org.springframework.integration:spring-integration-ftp/ org.springframework.integration:spring-integration-gemfire/ org.springframework.integration:spring-integration-groovy/ org.springframework.integration:spring-integration-http/ org.springframework.integration:spring-integration-ip/ org.springframework.integration:spring-integration-jdbc/ org.springframework.integration:spring-integration-jms/ org.springframework.integration:spring-integration-jmx/ org.springframework.integration:spring-integration-jpa/ org.springframework.integration:spring-integration-kafka/ org.springframework.integration:spring-integration-mail/ org.springframework.integration:spring-integration-mongodb/ org.springframework.integration:spring-integration-mqtt/ org.springframework.integration:spring-integration-r2dbc/ org.springframework.integration:spring-integration-redis/ org.springframework.integration:spring-integration-rmi/ org.springframework.integration:spring-integration-rsocket/ org.springframework.integration:spring-integration-scripting/ org.springframework.integration:spring-integration-security/ org.springframework.integration:spring-integration-sftp/ org.springframework.integration:spring-integration-stomp/ org.springframework.integration:spring-integration-stream/ org.springframework.integration:spring-integration-syslog/ org.springframework.integration:spring-integration-test/ org.springframework.integration:spring-integration-test-support/ org.springframework.integration:spring-integration-webflux/ org.springframework.integration:spring-integration-websocket/ org.springframework.integration:spring-integration-ws/ org.springframework.integration:spring-integration-xml/ org.springframework.integration:spring-integration-xmpp/ org.springframework.integration:spring-integration-zeromq/ org.springframework.integration:spring-integration-zookeeper
TuxCare security update for org.springframework.integration (5 CVEs)
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server,
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server/
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
ash_authentication_oauth2_server,
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
ash_authentication_oauth2_server/
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload
Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload
Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints
Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints
org.springframework:spring, org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-r2dbc, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (8 CVEs)
org.springframework:spring/ org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-r2dbc/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (8 CVEs)
@vitejs/plugin-legacy, @vitejs/plugin-react, create-vite, vite
TuxCare security update for 4 packages (1 CVE)
@vitejs/plugin-legacy/ @vitejs/plugin-react/ create-vite/ vite
TuxCare security update for 4 packages (1 CVE)
org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (8 CVEs)
org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (8 CVEs)
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
libprotocol-http2-perl, libprotocol-http2-perl, libprotocol-http2-perl
libprotocol-http2-perl/ libprotocol-http2-perl/ libprotocol-http2-perl
jquery-mobile
TuxCare security update for jquery-mobile (1 CVE)
jquery-mobile
TuxCare security update for jquery-mobile (1 CVE)
org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (11 CVEs)
org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (11 CVEs)
exiv2
Updated exiv2 package fixes security vulnerabilities
python-pyasn1
Updated python-pyasn1 packages fix security vulnerabilities
python-pyasn1
Updated python-pyasn1 packages fix security vulnerabilities
apache-mod_auth_openidc, apache-mod_auth_openidc
Updated apache-mod_auth_openidc packages fix a security vulnerability
apache-mod_auth_openidc/ apache-mod_auth_openidc
Updated apache-mod_auth_openidc packages fix a security vulnerability
Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
org.springframework.graphql:spring-graphql, org.springframework.graphql:spring-graphql-test
TuxCare security update for org.springframework.graphql (3 CVEs)
org.springframework.graphql:spring-graphql/ org.springframework.graphql:spring-graphql-test
TuxCare security update for org.springframework.graphql (3 CVEs)
Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
org.springframework.security:spring-security-acl, org.springframework.security:spring-security-aspects, org.springframework.security:spring-security-bom, org.springframework.security:spring-security-config, org.springframework.security:spring-security-core, org.springframework.security:spring-security-crypto, org.springframework.security:spring-security-data, org.springframework.security:spring-security-ldap, org.springframework.security:spring-security-messaging, org.springframework.security:spring-security-oauth2-client, org.springframework.security:spring-security-oauth2-core, org.springframework.security:spring-security-oauth2-jose, org.springframework.security:spring-security-oauth2-resource-server, org.springframework.security:spring-security-rsocket, org.springframework.security:spring-security-saml2-service-provider, org.springframework.security:spring-security-taglibs, org.springframework.security:spring-security-test, org.springframework.security:spring-security-web
TuxCare security update for org.springframework.security (2 CVEs)
org.springframework.security:spring-security-acl/ org.springframework.security:spring-security-aspects/ org.springframework.security:spring-security-bom/ org.springframework.security:spring-security-config/ org.springframework.security:spring-security-core/ org.springframework.security:spring-security-crypto/ org.springframework.security:spring-security-data/ org.springframework.security:spring-security-ldap/ org.springframework.security:spring-security-messaging/ org.springframework.security:spring-security-oauth2-client/ org.springframework.security:spring-security-oauth2-core/ org.springframework.security:spring-security-oauth2-jose/ org.springframework.security:spring-security-oauth2-resource-server/ org.springframework.security:spring-security-rsocket/ org.springframework.security:spring-security-saml2-service-provider/ org.springframework.security:spring-security-taglibs/ org.springframework.security:spring-security-test/ org.springframework.security:spring-security-web
TuxCare security update for org.springframework.security (2 CVEs)
org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (14 CVEs)
org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (14 CVEs)
org.springframework:spring, org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-r2dbc, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (3 CVEs)
org.springframework:spring/ org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-r2dbc/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (3 CVEs)
starlette, rootio-starlette
CVE-2023-30798 in starlette - Patched by Root
starlette/ rootio-starlette
CVE-2023-30798 in starlette - Patched by Root
starlette, rootio-starlette
CVE-2025-54121 in starlette - Patched by Root
starlette/ rootio-starlette
CVE-2025-54121 in starlette - Patched by Root
starlette
GHSA-3qj8-93xh-pwh2 in starlette - Patched by Root
starlette
GHSA-3qj8-93xh-pwh2 in starlette - Patched by Root
starlette
GHSA-qj8w-rv5x-2v9h in starlette - Patched by Root
starlette
GHSA-qj8w-rv5x-2v9h in starlette - Patched by Root
org.springframework:spring, org.springframework:spring-aop, org.springframework:spring-aspects, org.springframework:spring-beans, org.springframework:spring-context, org.springframework:spring-context-indexer, org.springframework:spring-context-support, org.springframework:spring-core, org.springframework:spring-expression, org.springframework:spring-framework-bom, org.springframework:spring-instrument, org.springframework:spring-jcl, org.springframework:spring-jdbc, org.springframework:spring-jms, org.springframework:spring-messaging, org.springframework:spring-orm, org.springframework:spring-oxm, org.springframework:spring-r2dbc, org.springframework:spring-test, org.springframework:spring-tx, org.springframework:spring-web, org.springframework:spring-webflux, org.springframework:spring-webmvc, org.springframework:spring-websocket
TuxCare security update for org.springframework (7 CVEs)
org.springframework:spring/ org.springframework:spring-aop/ org.springframework:spring-aspects/ org.springframework:spring-beans/ org.springframework:spring-context/ org.springframework:spring-context-indexer/ org.springframework:spring-context-support/ org.springframework:spring-core/ org.springframework:spring-expression/ org.springframework:spring-framework-bom/ org.springframework:spring-instrument/ org.springframework:spring-jcl/ org.springframework:spring-jdbc/ org.springframework:spring-jms/ org.springframework:spring-messaging/ org.springframework:spring-orm/ org.springframework:spring-oxm/ org.springframework:spring-r2dbc/ org.springframework:spring-test/ org.springframework:spring-tx/ org.springframework:spring-web/ org.springframework:spring-webflux/ org.springframework:spring-webmvc/ org.springframework:spring-websocket
TuxCare security update for org.springframework (7 CVEs)
