Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2025-0495 created 2 months ago Secrets leakage to telemetry endpoint via cache backend configuration via buildx Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication. buildx =<0.21.2 pkgs.docker-buildx Docker CLI plugin for extended build capabilities with BuildKit nixos-24.05 0.14.0 nixpkgs-24.05-darwin 0.14.0 nixos-24.05-small 0.14.0 nixos-24.11 0.18.0 nixpkgs-24.11-darwin 0.18.0 nixos-24.11-small 0.18.0 nixos-unstable 0.18.0 nixos-unstable-small 0.18.0 nixpkgs-unstable 0.18.0 CVE-2023-5215 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 1 week ago Libnbd: crash or misbehaviour when nbd server returns an unexpected block size A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for NBD clients that doesn't treat the return value of the nbd_get_size() function correctly. libnbd * virt:av/libnbd virt:rhel/libnbd virt-devel:av/libnbd pkgs.libnbd Network Block Device client library in userspace nixos-24.05 1.20.2 nixpkgs-24.05-darwin 1.20.2 nixos-24.05-small 1.20.2 nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2 pkgs.python311Packages.libnbd Network Block Device client library in userspace nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2 pkgs.python312Packages.libnbd Network Block Device client library in userspace nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2 CVE-2024-4028 3.8 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 1 week ago Keycloak-core: stored xss in keycloak when creating a items in admin console A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack. keycloak <18.0.8 keycloak-core pkgs.keycloak Identity and access management for modern applications and services nixos-24.05 25.0.6 nixpkgs-24.05-darwin 25.0.6 nixos-24.05-small 25.0.6 nixos-24.11 26.0.6 nixpkgs-24.11-darwin 26.0.7 nixos-24.11-small 26.0.7 nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6 pkgs.terraform-providers.keycloak nixos-24.05 4.4.0 nixpkgs-24.05-darwin 4.4.0 nixos-24.05-small 4.4.0 nixos-24.11 4.4.0 nixpkgs-24.11-darwin 4.4.0 nixos-24.11-small 4.4.0 nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0 pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 CVE-2025-2157 3.3 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 2 months, 1 week ago Foreman: disclosure of executed commands and outputs in foreman / red hat satellite A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively. foreman pkgs.foreman Process manager for applications with multiple components nixos-24.05 0.87.2 nixpkgs-24.05-darwin 0.87.2 nixos-24.05-small 0.87.2 nixos-24.11 0.87.2 nixpkgs-24.11-darwin 0.87.2 nixos-24.11-small 0.87.2 nixos-unstable 0.87.2 nixos-unstable-small 0.87.2 nixpkgs-unstable 0.87.2 pkgs.emacsPackages.foreman-mode nixos-24.05 20170725.1422 nixpkgs-24.05-darwin 20170725.1422 nixos-24.05-small 20170725.1422 nixos-24.11 20170725.1422 nixpkgs-24.11-darwin 20170725.1422 nixos-24.11-small 20170725.1422 nixos-unstable 20170725.1422 nixos-unstable-small 20170725.1422 nixpkgs-unstable 20170725.1422 CVE-2023-6787 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): NONE created 2 months, 1 week ago Keycloak: session hijacking via re-authentication A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session. keycloak <22.0.10 <24.0.3 keycloak-core rhbk/keycloak-rhel9 * rhbk/keycloak-rhel9-operator * rhbk/keycloak-operator-bundle * pkgs.keycloak Identity and access management for modern applications and services nixos-24.05 25.0.6 nixpkgs-24.05-darwin 25.0.6 nixos-24.05-small 25.0.6 nixos-24.11 26.0.6 nixpkgs-24.11-darwin 26.0.7 nixos-24.11-small 26.0.7 nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6 pkgs.terraform-providers.keycloak nixos-24.05 4.4.0 nixpkgs-24.05-darwin 4.4.0 nixos-24.05-small 4.4.0 nixos-24.11 4.4.0 nixpkgs-24.11-darwin 4.4.0 nixos-24.11-small 4.4.0 nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0 pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 CVE-2022-28652 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 1 week ago ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack apport <2.21.0 pkgs.texlivePackages.skrapport 'Simple' class for reports, etc. nixos-24.05 0.12k nixpkgs-24.05-darwin 0.12k nixos-24.05-small 0.12k pkgs.haskellPackages.apportionment Round a set of numbers while maintaining its sum nixos-24.05 0.0.0.4 nixpkgs-24.05-darwin 0.0.0.4 nixos-24.05-small 0.0.0.4 nixos-24.11 0.0.0.4 nixpkgs-24.11-darwin 0.0.0.4 nixos-24.11-small 0.0.0.4 nixos-unstable 0.0.0.4 nixos-unstable-small 0.0.0.4 nixpkgs-unstable 0.0.0.4 CVE-2025-0650 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 1 week ago Ovn: egress acls may be bypassed via specially crafted udp packet A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network. ovn ==22.03.8 ==24.03.5 ==24.09.2 ovn2.11 ovn2.12 ovn2.13 ovn-2021 ovn22.03 * ovn22.06 * ovn22.09 * ovn22.12 * ovn23.03 * ovn23.06 * ovn23.09 * ovn24.03 * ovn24.09 * pkgs.ovn Open Virtual Network nixos-24.11 24.09.1 nixpkgs-24.11-darwin 24.09.1 nixos-24.11-small 24.09.1 nixos-unstable 24.09.1 nixos-unstable-small 24.09.1 nixpkgs-unstable 24.09.1 pkgs.novnc VNC client web application nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0 pkgs.ovn-lts Open Virtual Network nixos-24.05 24.03.2 nixpkgs-24.05-darwin 24.03.2 nixos-24.05-small 24.03.2 pkgs.turbovnc High-speed version of VNC derived from TightVNC nixos-24.05 3.1 nixpkgs-24.05-darwin 3.1 nixos-24.05-small 3.1 nixos-24.11 3.1.2 nixpkgs-24.11-darwin 3.1.2 nixos-24.11-small 3.1.2 nixos-unstable 3.1.3 nixos-unstable-small 3.1.3 nixpkgs-unstable 3.1.3 pkgs.nanovna-saver A tool for reading, displaying and saving data from the NanoVNA nixos-24.05 0.6.3 nixpkgs-24.05-darwin 0.6.3 nixos-24.05-small 0.6.3 nixos-24.11 0.6.4 nixpkgs-24.11-darwin 0.6.4 nixos-24.11-small 0.6.4 nixos-unstable 0.6.5 nixos-unstable-small 0.6.5 nixpkgs-unstable 0.6.5 pkgs.python311Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 nixos-24.11 0.6.0 nixpkgs-24.11-darwin 0.6.0 nixos-24.11-small 0.6.0 nixos-unstable 0.6.0 nixos-unstable-small 0.6.0 nixpkgs-unstable 0.6.0 pkgs.python312Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 CVE-2024-2313 2.8 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 1 week ago If kernel headers need to be extracted, bpftrace will attempt … If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default. bpftrace <v0.20.2 pkgs.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.linuxPackages_zen.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.emacsPackages.bpftrace-mode nixos-24.05 20190608.2201 nixpkgs-24.05-darwin 20190608.2201 nixos-24.05-small 20190608.2201 nixos-24.11 20190608.2201 nixpkgs-24.11-darwin 20190608.2201 nixos-24.11-small 20190608.2201 nixos-unstable 20190608.2201 nixos-unstable-small 20190608.2201 nixpkgs-unstable 20190608.2201 pkgs.linuxKernel.packages.linux_6_1.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 pkgs.linuxKernel.packages.linux_lqx.bpftrace High-level tracing language for Linux eBPF nixos-24.11 ??? nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 pkgs.linuxKernel.packages.linux_4_19.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 pkgs.linuxKernel.packages.linux_5_10.bpftrace High-level tracing language for Linux eBPF nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.linuxKernel.packages.linux_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-24.11 0.21.2 nixos-unstable 0.21.2 pkgs.linuxKernel.packages.linux_hardened.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 pkgs.linuxKernel.packages.linux_latest_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 CVE-2024-43437 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 1 week ago Moodle: xss risk when restoring malicious course backup file A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. moodle <4.2.9 <4.4.2 <4.1.12 <4.3.6 pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-24.05 4.4 nixpkgs-24.05-darwin 4.4 nixos-24.05-small 4.4 nixos-24.11 4.4.3 nixpkgs-24.11-darwin 4.4.3 nixos-24.11-small 4.4.3 nixos-unstable 4.4.3 nixos-unstable-small 4.4.4 nixpkgs-unstable 4.4.3 pkgs.moodle-dl A Moodle downloader that downloads course content fast from Moodle nixos-24.05 2.2.2.4 nixpkgs-24.05-darwin 2.2.2.4 nixos-24.05-small 2.2.2.4 nixos-24.11 2.3.12 nixpkgs-24.11-darwin 2.3.12 nixos-24.11-small 2.3.12 nixos-unstable 2.3.12 nixos-unstable-small 2.3.12 nixpkgs-unstable 2.3.12 pkgs.texlivePackages.moodle Generating Moodle quizzes via LaTeX nixos-24.05 1.0 nixpkgs-24.05-darwin 1.0 nixos-24.05-small 1.0 CVE-2023-26020 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 1 week ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Crafter Studio Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26. Studio =<4.0.1 =<3.1.26 pkgs.rstudio Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764 pkgs.rstudio-server Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764 pkgs.rstudioWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper pkgs.rstudioServerWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-24.05 1.2.30 nixpkgs-24.05-darwin 1.2.30 nixos-24.05-small 1.2.30 nixos-24.11 1.3.2 nixpkgs-24.11-darwin 1.3.2 nixos-24.11-small 1.3.2 nixos-unstable 1.3.2 nixos-unstable-small 1.3.2 nixpkgs-unstable 1.3.2 pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-24.05 0.2.8 nixpkgs-24.05-darwin 0.2.8 nixos-24.05-small 0.2.8 nixos-24.11 0.2.9 nixpkgs-24.11-darwin 0.2.9 nixos-24.11-small 0.2.9 nixos-unstable 0.2.9 nixos-unstable-small 0.2.9 nixpkgs-unstable 0.2.9
CVE-2025-0495 created 2 months ago Secrets leakage to telemetry endpoint via cache backend configuration via buildx Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication. buildx =<0.21.2 pkgs.docker-buildx Docker CLI plugin for extended build capabilities with BuildKit nixos-24.05 0.14.0 nixpkgs-24.05-darwin 0.14.0 nixos-24.05-small 0.14.0 nixos-24.11 0.18.0 nixpkgs-24.11-darwin 0.18.0 nixos-24.11-small 0.18.0 nixos-unstable 0.18.0 nixos-unstable-small 0.18.0 nixpkgs-unstable 0.18.0
pkgs.docker-buildx Docker CLI plugin for extended build capabilities with BuildKit nixos-24.05 0.14.0 nixpkgs-24.05-darwin 0.14.0 nixos-24.05-small 0.14.0 nixos-24.11 0.18.0 nixpkgs-24.11-darwin 0.18.0 nixos-24.11-small 0.18.0 nixos-unstable 0.18.0 nixos-unstable-small 0.18.0 nixpkgs-unstable 0.18.0
CVE-2023-5215 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 1 week ago Libnbd: crash or misbehaviour when nbd server returns an unexpected block size A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for NBD clients that doesn't treat the return value of the nbd_get_size() function correctly. libnbd * virt:av/libnbd virt:rhel/libnbd virt-devel:av/libnbd pkgs.libnbd Network Block Device client library in userspace nixos-24.05 1.20.2 nixpkgs-24.05-darwin 1.20.2 nixos-24.05-small 1.20.2 nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2 pkgs.python311Packages.libnbd Network Block Device client library in userspace nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2 pkgs.python312Packages.libnbd Network Block Device client library in userspace nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2
pkgs.libnbd Network Block Device client library in userspace nixos-24.05 1.20.2 nixpkgs-24.05-darwin 1.20.2 nixos-24.05-small 1.20.2 nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2
pkgs.python311Packages.libnbd Network Block Device client library in userspace nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2
pkgs.python312Packages.libnbd Network Block Device client library in userspace nixos-24.11 1.20.2 nixpkgs-24.11-darwin 1.20.2 nixos-24.11-small 1.20.2 nixos-unstable 1.20.2 nixos-unstable-small 1.20.2 nixpkgs-unstable 1.20.2
CVE-2024-4028 3.8 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 1 week ago Keycloak-core: stored xss in keycloak when creating a items in admin console A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack. keycloak <18.0.8 keycloak-core pkgs.keycloak Identity and access management for modern applications and services nixos-24.05 25.0.6 nixpkgs-24.05-darwin 25.0.6 nixos-24.05-small 25.0.6 nixos-24.11 26.0.6 nixpkgs-24.11-darwin 26.0.7 nixos-24.11-small 26.0.7 nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6 pkgs.terraform-providers.keycloak nixos-24.05 4.4.0 nixpkgs-24.05-darwin 4.4.0 nixos-24.05-small 4.4.0 nixos-24.11 4.4.0 nixpkgs-24.11-darwin 4.4.0 nixos-24.11-small 4.4.0 nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0 pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.keycloak Identity and access management for modern applications and services nixos-24.05 25.0.6 nixpkgs-24.05-darwin 25.0.6 nixos-24.05-small 25.0.6 nixos-24.11 26.0.6 nixpkgs-24.11-darwin 26.0.7 nixos-24.11-small 26.0.7 nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6
pkgs.terraform-providers.keycloak nixos-24.05 4.4.0 nixpkgs-24.05-darwin 4.4.0 nixos-24.05-small 4.4.0 nixos-24.11 4.4.0 nixpkgs-24.11-darwin 4.4.0 nixos-24.11-small 4.4.0 nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0
pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
CVE-2025-2157 3.3 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 2 months, 1 week ago Foreman: disclosure of executed commands and outputs in foreman / red hat satellite A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively. foreman pkgs.foreman Process manager for applications with multiple components nixos-24.05 0.87.2 nixpkgs-24.05-darwin 0.87.2 nixos-24.05-small 0.87.2 nixos-24.11 0.87.2 nixpkgs-24.11-darwin 0.87.2 nixos-24.11-small 0.87.2 nixos-unstable 0.87.2 nixos-unstable-small 0.87.2 nixpkgs-unstable 0.87.2 pkgs.emacsPackages.foreman-mode nixos-24.05 20170725.1422 nixpkgs-24.05-darwin 20170725.1422 nixos-24.05-small 20170725.1422 nixos-24.11 20170725.1422 nixpkgs-24.11-darwin 20170725.1422 nixos-24.11-small 20170725.1422 nixos-unstable 20170725.1422 nixos-unstable-small 20170725.1422 nixpkgs-unstable 20170725.1422
pkgs.foreman Process manager for applications with multiple components nixos-24.05 0.87.2 nixpkgs-24.05-darwin 0.87.2 nixos-24.05-small 0.87.2 nixos-24.11 0.87.2 nixpkgs-24.11-darwin 0.87.2 nixos-24.11-small 0.87.2 nixos-unstable 0.87.2 nixos-unstable-small 0.87.2 nixpkgs-unstable 0.87.2
pkgs.emacsPackages.foreman-mode nixos-24.05 20170725.1422 nixpkgs-24.05-darwin 20170725.1422 nixos-24.05-small 20170725.1422 nixos-24.11 20170725.1422 nixpkgs-24.11-darwin 20170725.1422 nixos-24.11-small 20170725.1422 nixos-unstable 20170725.1422 nixos-unstable-small 20170725.1422 nixpkgs-unstable 20170725.1422
CVE-2023-6787 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): NONE created 2 months, 1 week ago Keycloak: session hijacking via re-authentication A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session. keycloak <22.0.10 <24.0.3 keycloak-core rhbk/keycloak-rhel9 * rhbk/keycloak-rhel9-operator * rhbk/keycloak-operator-bundle * pkgs.keycloak Identity and access management for modern applications and services nixos-24.05 25.0.6 nixpkgs-24.05-darwin 25.0.6 nixos-24.05-small 25.0.6 nixos-24.11 26.0.6 nixpkgs-24.11-darwin 26.0.7 nixos-24.11-small 26.0.7 nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6 pkgs.terraform-providers.keycloak nixos-24.05 4.4.0 nixpkgs-24.05-darwin 4.4.0 nixos-24.05-small 4.4.0 nixos-24.11 4.4.0 nixpkgs-24.11-darwin 4.4.0 nixos-24.11-small 4.4.0 nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0 pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.keycloak Identity and access management for modern applications and services nixos-24.05 25.0.6 nixpkgs-24.05-darwin 25.0.6 nixos-24.05-small 25.0.6 nixos-24.11 26.0.6 nixpkgs-24.11-darwin 26.0.7 nixos-24.11-small 26.0.7 nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6
pkgs.terraform-providers.keycloak nixos-24.05 4.4.0 nixpkgs-24.05-darwin 4.4.0 nixos-24.05-small 4.4.0 nixos-24.11 4.4.0 nixpkgs-24.11-darwin 4.4.0 nixos-24.11-small 4.4.0 nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0
pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-24.05 4.0.0 nixpkgs-24.05-darwin 4.0.0 nixos-24.05-small 4.0.0 nixos-24.11 4.0.0 nixpkgs-24.11-darwin 4.0.0 nixos-24.11-small 4.0.0 nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
CVE-2022-28652 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 1 week ago ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack apport <2.21.0 pkgs.texlivePackages.skrapport 'Simple' class for reports, etc. nixos-24.05 0.12k nixpkgs-24.05-darwin 0.12k nixos-24.05-small 0.12k pkgs.haskellPackages.apportionment Round a set of numbers while maintaining its sum nixos-24.05 0.0.0.4 nixpkgs-24.05-darwin 0.0.0.4 nixos-24.05-small 0.0.0.4 nixos-24.11 0.0.0.4 nixpkgs-24.11-darwin 0.0.0.4 nixos-24.11-small 0.0.0.4 nixos-unstable 0.0.0.4 nixos-unstable-small 0.0.0.4 nixpkgs-unstable 0.0.0.4
pkgs.texlivePackages.skrapport 'Simple' class for reports, etc. nixos-24.05 0.12k nixpkgs-24.05-darwin 0.12k nixos-24.05-small 0.12k
pkgs.haskellPackages.apportionment Round a set of numbers while maintaining its sum nixos-24.05 0.0.0.4 nixpkgs-24.05-darwin 0.0.0.4 nixos-24.05-small 0.0.0.4 nixos-24.11 0.0.0.4 nixpkgs-24.11-darwin 0.0.0.4 nixos-24.11-small 0.0.0.4 nixos-unstable 0.0.0.4 nixos-unstable-small 0.0.0.4 nixpkgs-unstable 0.0.0.4
CVE-2025-0650 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 1 week ago Ovn: egress acls may be bypassed via specially crafted udp packet A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network. ovn ==22.03.8 ==24.03.5 ==24.09.2 ovn2.11 ovn2.12 ovn2.13 ovn-2021 ovn22.03 * ovn22.06 * ovn22.09 * ovn22.12 * ovn23.03 * ovn23.06 * ovn23.09 * ovn24.03 * ovn24.09 * pkgs.ovn Open Virtual Network nixos-24.11 24.09.1 nixpkgs-24.11-darwin 24.09.1 nixos-24.11-small 24.09.1 nixos-unstable 24.09.1 nixos-unstable-small 24.09.1 nixpkgs-unstable 24.09.1 pkgs.novnc VNC client web application nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0 pkgs.ovn-lts Open Virtual Network nixos-24.05 24.03.2 nixpkgs-24.05-darwin 24.03.2 nixos-24.05-small 24.03.2 pkgs.turbovnc High-speed version of VNC derived from TightVNC nixos-24.05 3.1 nixpkgs-24.05-darwin 3.1 nixos-24.05-small 3.1 nixos-24.11 3.1.2 nixpkgs-24.11-darwin 3.1.2 nixos-24.11-small 3.1.2 nixos-unstable 3.1.3 nixos-unstable-small 3.1.3 nixpkgs-unstable 3.1.3 pkgs.nanovna-saver A tool for reading, displaying and saving data from the NanoVNA nixos-24.05 0.6.3 nixpkgs-24.05-darwin 0.6.3 nixos-24.05-small 0.6.3 nixos-24.11 0.6.4 nixpkgs-24.11-darwin 0.6.4 nixos-24.11-small 0.6.4 nixos-unstable 0.6.5 nixos-unstable-small 0.6.5 nixpkgs-unstable 0.6.5 pkgs.python311Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 nixos-24.11 0.6.0 nixpkgs-24.11-darwin 0.6.0 nixos-24.11-small 0.6.0 nixos-unstable 0.6.0 nixos-unstable-small 0.6.0 nixpkgs-unstable 0.6.0 pkgs.python312Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0
pkgs.ovn Open Virtual Network nixos-24.11 24.09.1 nixpkgs-24.11-darwin 24.09.1 nixos-24.11-small 24.09.1 nixos-unstable 24.09.1 nixos-unstable-small 24.09.1 nixpkgs-unstable 24.09.1
pkgs.novnc VNC client web application nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0
pkgs.ovn-lts Open Virtual Network nixos-24.05 24.03.2 nixpkgs-24.05-darwin 24.03.2 nixos-24.05-small 24.03.2
pkgs.turbovnc High-speed version of VNC derived from TightVNC nixos-24.05 3.1 nixpkgs-24.05-darwin 3.1 nixos-24.05-small 3.1 nixos-24.11 3.1.2 nixpkgs-24.11-darwin 3.1.2 nixos-24.11-small 3.1.2 nixos-unstable 3.1.3 nixos-unstable-small 3.1.3 nixpkgs-unstable 3.1.3
pkgs.nanovna-saver A tool for reading, displaying and saving data from the NanoVNA nixos-24.05 0.6.3 nixpkgs-24.05-darwin 0.6.3 nixos-24.05-small 0.6.3 nixos-24.11 0.6.4 nixpkgs-24.11-darwin 0.6.4 nixos-24.11-small 0.6.4 nixos-unstable 0.6.5 nixos-unstable-small 0.6.5 nixpkgs-unstable 0.6.5
pkgs.python311Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 nixos-24.11 0.6.0 nixpkgs-24.11-darwin 0.6.0 nixos-24.11-small 0.6.0 nixos-unstable 0.6.0 nixos-unstable-small 0.6.0 nixpkgs-unstable 0.6.0
pkgs.python312Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0
CVE-2024-2313 2.8 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 2 months, 1 week ago If kernel headers need to be extracted, bpftrace will attempt … If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default. bpftrace <v0.20.2 pkgs.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.linuxPackages_zen.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.emacsPackages.bpftrace-mode nixos-24.05 20190608.2201 nixpkgs-24.05-darwin 20190608.2201 nixos-24.05-small 20190608.2201 nixos-24.11 20190608.2201 nixpkgs-24.11-darwin 20190608.2201 nixos-24.11-small 20190608.2201 nixos-unstable 20190608.2201 nixos-unstable-small 20190608.2201 nixpkgs-unstable 20190608.2201 pkgs.linuxKernel.packages.linux_6_1.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 pkgs.linuxKernel.packages.linux_lqx.bpftrace High-level tracing language for Linux eBPF nixos-24.11 ??? nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 pkgs.linuxKernel.packages.linux_4_19.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 pkgs.linuxKernel.packages.linux_5_10.bpftrace High-level tracing language for Linux eBPF nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.linuxKernel.packages.linux_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-24.11 0.21.2 nixos-unstable 0.21.2 pkgs.linuxKernel.packages.linux_hardened.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 pkgs.linuxKernel.packages.linux_latest_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
pkgs.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
pkgs.linuxPackages_zen.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
pkgs.emacsPackages.bpftrace-mode nixos-24.05 20190608.2201 nixpkgs-24.05-darwin 20190608.2201 nixos-24.05-small 20190608.2201 nixos-24.11 20190608.2201 nixpkgs-24.11-darwin 20190608.2201 nixos-24.11-small 20190608.2201 nixos-unstable 20190608.2201 nixos-unstable-small 20190608.2201 nixpkgs-unstable 20190608.2201
pkgs.linuxKernel.packages.linux_6_1.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2
pkgs.linuxKernel.packages.linux_lqx.bpftrace High-level tracing language for Linux eBPF nixos-24.11 ??? nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2
pkgs.linuxKernel.packages.linux_4_19.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4
pkgs.linuxKernel.packages.linux_5_10.bpftrace High-level tracing language for Linux eBPF nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
pkgs.linuxKernel.packages.linux_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-24.11 0.21.2 nixos-unstable 0.21.2
pkgs.linuxKernel.packages.linux_hardened.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4
pkgs.linuxKernel.packages.linux_latest_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
CVE-2024-43437 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 1 week ago Moodle: xss risk when restoring malicious course backup file A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. moodle <4.2.9 <4.4.2 <4.1.12 <4.3.6 pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-24.05 4.4 nixpkgs-24.05-darwin 4.4 nixos-24.05-small 4.4 nixos-24.11 4.4.3 nixpkgs-24.11-darwin 4.4.3 nixos-24.11-small 4.4.3 nixos-unstable 4.4.3 nixos-unstable-small 4.4.4 nixpkgs-unstable 4.4.3 pkgs.moodle-dl A Moodle downloader that downloads course content fast from Moodle nixos-24.05 2.2.2.4 nixpkgs-24.05-darwin 2.2.2.4 nixos-24.05-small 2.2.2.4 nixos-24.11 2.3.12 nixpkgs-24.11-darwin 2.3.12 nixos-24.11-small 2.3.12 nixos-unstable 2.3.12 nixos-unstable-small 2.3.12 nixpkgs-unstable 2.3.12 pkgs.texlivePackages.moodle Generating Moodle quizzes via LaTeX nixos-24.05 1.0 nixpkgs-24.05-darwin 1.0 nixos-24.05-small 1.0
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-24.05 4.4 nixpkgs-24.05-darwin 4.4 nixos-24.05-small 4.4 nixos-24.11 4.4.3 nixpkgs-24.11-darwin 4.4.3 nixos-24.11-small 4.4.3 nixos-unstable 4.4.3 nixos-unstable-small 4.4.4 nixpkgs-unstable 4.4.3
pkgs.moodle-dl A Moodle downloader that downloads course content fast from Moodle nixos-24.05 2.2.2.4 nixpkgs-24.05-darwin 2.2.2.4 nixos-24.05-small 2.2.2.4 nixos-24.11 2.3.12 nixpkgs-24.11-darwin 2.3.12 nixos-24.11-small 2.3.12 nixos-unstable 2.3.12 nixos-unstable-small 2.3.12 nixpkgs-unstable 2.3.12
pkgs.texlivePackages.moodle Generating Moodle quizzes via LaTeX nixos-24.05 1.0 nixpkgs-24.05-darwin 1.0 nixos-24.05-small 1.0
CVE-2023-26020 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): HIGH created 2 months, 1 week ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Crafter Studio Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26. Studio =<4.0.1 =<3.1.26 pkgs.rstudio Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764 pkgs.rstudio-server Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764 pkgs.rstudioWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper pkgs.rstudioServerWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-24.05 1.2.30 nixpkgs-24.05-darwin 1.2.30 nixos-24.05-small 1.2.30 nixos-24.11 1.3.2 nixpkgs-24.11-darwin 1.3.2 nixos-24.11-small 1.3.2 nixos-unstable 1.3.2 nixos-unstable-small 1.3.2 nixpkgs-unstable 1.3.2 pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-24.05 0.2.8 nixpkgs-24.05-darwin 0.2.8 nixos-24.05-small 0.2.8 nixos-24.11 0.2.9 nixpkgs-24.11-darwin 0.2.9 nixos-24.11-small 0.2.9 nixos-unstable 0.2.9 nixos-unstable-small 0.2.9 nixpkgs-unstable 0.2.9
pkgs.rstudio Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764
pkgs.rstudio-server Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764
pkgs.rstudioWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper
pkgs.rstudioServerWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper
pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-24.05 1.2.30 nixpkgs-24.05-darwin 1.2.30 nixos-24.05-small 1.2.30 nixos-24.11 1.3.2 nixpkgs-24.11-darwin 1.3.2 nixos-24.11-small 1.3.2 nixos-unstable 1.3.2 nixos-unstable-small 1.3.2 nixpkgs-unstable 1.3.2
pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-24.05 0.2.8 nixpkgs-24.05-darwin 0.2.8 nixos-24.05-small 0.2.8 nixos-24.11 0.2.9 nixpkgs-24.11-darwin 0.2.9 nixos-24.11-small 0.2.9 nixos-unstable 0.2.9 nixos-unstable-small 0.2.9 nixpkgs-unstable 0.2.9