Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2024-7006 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 3 weeks ago Libtiff: null pointer dereference in tif_dirinfo.c A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service. libtiff * pkgs.libtiff Library and utilities for working with the TIFF image file format nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 4.7.0 nixpkgs-24.11-darwin 4.7.0 nixos-24.11-small 4.7.0 nixos-unstable 4.7.0 nixos-unstable-small 4.7.0 nixpkgs-unstable 4.7.0 pkgs.libtiff_t Library and utilities for working with the TIFF image file format (fork containing tools dropped in original libtiff version) nixos-24.05 4.6.0t nixpkgs-24.05-darwin 4.6.0t nixos-24.05-small 4.6.0t Notify package maintainers: 7 @nialov Nikolas Ovaskainen <nikolasovaskainen@gmail.com> @nh2 Niklas Hambüchen <mail@nh2.me> @imincik Ivan Mincik <ivan.mincik@gmail.com> @l0b0 Victor Engmark <victor@engmark.name> @willcohen Will Cohen @sikmir Nikolay Korotkiy <sikmir@disroot.org> @Yarny0 Yarny CVE-2022-47161 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 3 weeks ago WordPress Health Check & Troubleshooting Plugin <= 1.5.1 is vulnerable to Cross Site Request Forgery (CSRF) Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions. health-check =<1.5.1 pkgs.health-check Process monitoring tool nixos-24.05 0.04.00 nixpkgs-24.05-darwin 0.04.00 nixos-24.05-small 0.04.00 nixos-24.11 0.04.00 nixpkgs-24.11-darwin 0.04.00 nixos-24.11-small 0.04.00 nixos-unstable 0.04.00 nixos-unstable-small 0.04.00 nixpkgs-unstable 0.04.00 pkgs.grpc-health-check Minimal, high performance, memory-friendly, safe implementation of the gRPC health checking protocol nixos-24.11 2022-08-19 nixpkgs-24.11-darwin 2022-08-19 nixos-24.11-small 2022-08-19 nixos-unstable 2022-08-19 nixos-unstable-small 2022-08-19 nixpkgs-unstable 2022-08-19 pkgs.python311Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-24.05 3.18.1 nixpkgs-24.05-darwin 3.18.1 nixos-24.05-small 3.18.1 nixos-24.11 3.18.3 nixpkgs-24.11-darwin 3.18.3 nixos-24.11-small 3.18.3 nixos-unstable 3.18.3 nixos-unstable-small 3.18.3 nixpkgs-unstable 3.18.3 pkgs.python312Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-24.05 3.18.1 nixpkgs-24.05-darwin 3.18.1 nixos-24.05-small 3.18.1 nixos-24.11 3.18.3 nixpkgs-24.11-darwin 3.18.3 nixos-24.11-small 3.18.3 nixos-unstable 3.18.3 nixos-unstable-small 3.18.3 nixpkgs-unstable 3.18.3 pkgs.rubyPackages.github-pages-health-check nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 pkgs.python311Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-24.05 1.62.2 nixpkgs-24.05-darwin 1.62.2 nixos-24.05-small 1.62.2 nixos-24.11 1.67.0 nixpkgs-24.11-darwin 1.67.0 nixos-24.11-small 1.67.0 nixos-unstable 1.67.0 nixos-unstable-small 1.67.0 nixpkgs-unstable 1.67.0 pkgs.python312Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-24.05 1.62.2 nixpkgs-24.05-darwin 1.62.2 nixos-24.05-small 1.62.2 nixos-24.11 1.67.0 nixpkgs-24.11-darwin 1.67.0 nixos-24.11-small 1.67.0 nixos-unstable 1.67.0 nixos-unstable-small 1.67.0 nixpkgs-unstable 1.67.0 pkgs.rubyPackages_3_1.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2 pkgs.rubyPackages_3_2.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2 pkgs.rubyPackages_3_3.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2 pkgs.rubyPackages_3_4.github-pages-health-check nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2 Notify package maintainers: 4 @dtzWill Will Dietz <w@wdtz.org> @flokli Florian Klink <flokli@flokli.de> @onny Jonas Heinrich <onny@project-insanity.org> @happysalada Raphael Megzari <raphael@megzari.com> CVE-2023-32550 9.3 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 3 weeks ago Landscape's Apache server-status is accessible by default Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API. landscape <19.10.05 pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Notify package maintainers: 3 @manveru Michael Fellinger <m.fellinger@gmail.com> @mbode Maximilian Bode <maxbode@gmail.com> @nicknovitski Nick Novitski <nixpkgs@nicknovitski.com> CVE-2023-32549 6.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 2 months, 3 weeks ago Landscape insecure token generation Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator. landscape <19.10.05 pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Notify package maintainers: 3 @manveru Michael Fellinger <m.fellinger@gmail.com> @mbode Maximilian Bode <maxbode@gmail.com> @nicknovitski Nick Novitski <nixpkgs@nicknovitski.com> CVE-2023-32551 6.1 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 3 weeks ago Landscape Open Redirect Landscape allowed URLs which caused open redirection. landscape <19.10.05 pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Notify package maintainers: 3 @manveru Michael Fellinger <m.fellinger@gmail.com> @mbode Maximilian Bode <maxbode@gmail.com> @nicknovitski Nick Novitski <nixpkgs@nicknovitski.com> CVE-2023-6277 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 4 weeks ago Libtiff: out-of-memory in tiffopen via a craft file An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB. iv tkimg libtiff mingw-libtiff compat-libtiff3 pkgs.libtiff Library and utilities for working with the TIFF image file format nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 4.7.0 nixpkgs-24.11-darwin 4.7.0 nixos-24.11-small 4.7.0 nixos-unstable 4.7.0 nixos-unstable-small 4.7.0 nixpkgs-unstable 4.7.0 pkgs.libtiff_t Library and utilities for working with the TIFF image file format (fork containing tools dropped in original libtiff version) nixos-24.05 4.6.0t nixpkgs-24.05-darwin 4.6.0t nixos-24.05-small 4.6.0t Notify package maintainers: 8 @l0b0 Victor Engmark <victor@engmark.name> @autra Augustin Trancart <augustin.trancart@gmail.com> @willcohen Will Cohen @nialov Nikolas Ovaskainen <nikolasovaskainen@gmail.com> @nh2 Niklas Hambüchen <mail@nh2.me> @sikmir Nikolay Korotkiy <sikmir@disroot.org> @imincik Ivan Mincik <ivan.mincik@gmail.com> @Yarny0 Yarny CVE-2023-6596 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 4 weeks ago Openshift: incomplete fix for rapid reset (cve-2023-44487/cve-2023-39325) An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers. openshift <4.12.48 <4.11.58 openshift4/ose-olm-rukpak-rhel8 openshift4/ose-operator-lifecycle-manager * pkgs.openshift Build, deploy, and manage your applications with Docker and Kubernetes nixos-24.05 4.14.0 nixpkgs-24.05-darwin 4.14.0 nixos-24.05-small 4.14.0 nixos-24.11 4.16.0 nixpkgs-24.11-darwin 4.16.0 nixos-24.11-small 4.16.0 nixos-unstable 4.16.0 nixos-unstable-small 4.16.0 nixpkgs-unstable 4.16.0 pkgs.python311Packages.openshift Python client for the OpenShift API nixos-24.05 0.13.2 nixpkgs-24.05-darwin 0.13.2 nixos-24.05-small 0.13.2 nixos-24.11 0.13.2 nixpkgs-24.11-darwin 0.13.2 nixos-24.11-small 0.13.2 nixos-unstable 0.13.2 nixos-unstable-small 0.13.2 nixpkgs-unstable 0.13.2 pkgs.python312Packages.openshift Python client for the OpenShift API nixos-24.05 0.13.2 nixpkgs-24.05-darwin 0.13.2 nixos-24.05-small 0.13.2 nixos-24.11 0.13.2 nixpkgs-24.11-darwin 0.13.2 nixos-24.11-small 0.13.2 nixos-unstable 0.13.2 nixos-unstable-small 0.13.2 nixpkgs-unstable 0.13.2 pkgs.python311Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0 pkgs.python312Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0 Notify package maintainers: 4 @stehessel Stephan Heßelmann <stephan@stehessel.de> @moretea Maarten Hoogendoorn <maarten@moretea.nl> @offlinehacker Jaka Hudoklin <jaka@x-truder.net> @teto Matthieu Coudron <mcoudron@hotmail.com> CVE-2024-45617 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized. opensc libopensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-24.05 0.26.0 nixpkgs-24.05-darwin 0.26.0 nixos-24.05-small 0.26.0 nixos-24.11 0.26.0 nixpkgs-24.11-darwin 0.26.0 nixos-24.11-small 0.26.0 nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0 pkgs.openscad 3D parametric model compiler nixos-24.05 2021.01 nixpkgs-24.05-darwin 2021.01 nixos-24.05-small 2021.01 nixos-24.11 2021.01 nixpkgs-24.11-darwin 2021.01 nixos-24.11-small 2021.01 nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-24.11 1.3.10 nixpkgs-24.11-darwin 1.3.10 nixos-24.11-small 1.3.10 nixos-unstable 1.3.10 nixos-unstable-small 1.3.10 nixpkgs-unstable 1.3.10 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-24.05 1.2.5 nixpkgs-24.05-darwin 1.2.5 nixos-24.05-small 1.2.5 nixos-24.11 1.2.5 nixpkgs-24.11-darwin 1.2.5 nixos-24.11-small 1.2.5 nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5 pkgs.openscenegraph 3D graphics toolkit nixos-24.05 3.6.5 nixpkgs-24.05-darwin 3.6.5 nixos-24.05-small 3.6.5 nixos-24.11 3.6.5 nixpkgs-24.11-darwin 3.6.5 nixos-24.11-small 3.6.5 nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-24.05 2024-03-10 nixpkgs-24.05-darwin 2024-03-10 nixos-24.05-small 2024-03-10 nixos-24.11 2024-11-10 nixpkgs-24.11-darwin 2024-11-10 nixos-24.11-small 2024-11-10 nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06 pkgs.vimPlugins.vim-openscad nixos-24.05 2022-07-26 nixpkgs-24.05-darwin 2022-07-26 nixos-24.05-small 2022-07-26 nixos-24.11 2022-07-26 nixpkgs-24.11-darwin 2022-07-26 nixos-24.11-small 2022-07-26 nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26 pkgs.vimPlugins.openscad-nvim nixos-24.05 2024-04-13 nixpkgs-24.05-darwin 2024-04-13 nixos-24.05-small 2024-04-13 nixos-24.11 2024-04-13 nixpkgs-24.11-darwin 2024-04-13 nixos-24.11-small 2024-04-13 nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13 pkgs.kakounePlugins.openscad-kak nixos-24.05 2020-12-10 nixpkgs-24.05-darwin 2020-12-10 nixos-24.05-small 2020-12-10 nixos-24.11 2020-12-10 nixpkgs-24.11-darwin 2020-12-10 nixos-24.11-small 2020-12-10 nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-24.05 1.1.1 nixpkgs-24.05-darwin 1.1.1 nixos-24.05-small 1.1.1 nixos-24.11 1.3.1 nixpkgs-24.11-darwin 1.3.1 nixos-24.11-small 1.3.1 nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1 Notify package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @gebner Gabriel Ebner <gebner@gebner.org> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @aanderse Aaron Andersen <aaron@fosslib.net> @pca006132 pca006132 <john.lck40@gmail.com> CVE-2024-38789 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago WordPress Telegram Bot & Channel plugin <= 3.8.2 - Cross Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Telegram Bot & Channel allows Cross Site Request Forgery.This issue affects Telegram Bot & Channel: from n/a through 3.8.2. telegram-bot =<3.8.2 pkgs.telegram-bot-api Telegram Bot API server nixos-24.05 7.3 nixpkgs-24.05-darwin 7.3 nixos-24.05-small 7.3 nixos-24.11 7.11 nixpkgs-24.11-darwin 7.11 nixos-24.11-small 7.11 nixos-unstable 8.0 nixos-unstable-small 8.0 nixpkgs-unstable 8.0 pkgs.haskellPackages.telegram-bot-api Easy to use library for building Telegram bots. Exports Telegram Bot API. nixos-24.05 7.0 nixpkgs-24.05-darwin 7.0 nixos-24.05-small 7.0 nixos-24.11 7.4.1 nixpkgs-24.11-darwin 7.4.1 nixos-24.11-small 7.4.1 nixos-unstable 7.4.1 nixos-unstable-small 7.4.1 nixpkgs-unstable 7.4.1 pkgs.haskellPackages.telegram-bot-simple Easy to use library for building Telegram bots nixos-24.05 0.13 nixpkgs-24.05-darwin 0.13 nixos-24.05-small 0.13 nixos-24.11 0.14.3 nixpkgs-24.11-darwin 0.14.3 nixos-24.11-small 0.14.3 nixos-unstable 0.14.3 nixos-unstable-small 0.14.3 nixpkgs-unstable 0.14.3 pkgs.python311Packages.python-telegram-bot Python library to interface with the Telegram Bot API nixos-24.05 21.2 nixpkgs-24.05-darwin 21.2 nixos-24.05-small 21.2 nixos-24.11 21.7 nixpkgs-24.11-darwin 21.7 nixos-24.11-small 21.7 nixos-unstable 21.7 nixos-unstable-small 21.7 nixpkgs-unstable 21.7 pkgs.python312Packages.python-telegram-bot Python library to interface with the Telegram Bot API nixos-24.05 21.2 nixpkgs-24.05-darwin 21.2 nixos-24.05-small 21.2 nixos-24.11 21.7 nixpkgs-24.11-darwin 21.7 nixos-24.11-small 21.7 nixos-unstable 21.7 nixos-unstable-small 21.7 nixpkgs-unstable 21.7 Notify package maintainers: 4 @Anillc Anillc <i@anillc.cn> @Forden Forden <forden@zuku.tech> @veprbl Dmitry Kalinkin <veprbl@gmail.com> @pingiun Jelle Besseling <nixos@pingiun.com> CVE-2024-38766 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago WordPress Matomo Analytics plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) leading to Notice Dismissal vulnerability Cross-Site Request Forgery (CSRF) vulnerability in Matomo Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from n/a through 5.1.1. matomo =<5.1.1 pkgs.matomo A real-time web analytics application nixos-24.05 4.16.1 nixpkgs-24.05-darwin 4.16.1 nixos-24.05-small 4.16.1 nixos-24.11 4.16.1 nixpkgs-24.11-darwin 4.16.1 nixos-24.11-small 4.16.1 nixos-unstable 4.16.1 nixos-unstable-small 4.16.1 nixpkgs-unstable 4.16.1 pkgs.matomo_5 Real-time web analytics application nixos-24.05 5.1.1 nixpkgs-24.05-darwin 5.1.1 nixos-24.05-small 5.1.1 nixos-24.11 5.1.1 nixpkgs-24.11-darwin 5.1.2 nixos-24.11-small 5.1.2 nixos-unstable 5.1.1 nixos-unstable-small 5.1.2 nixpkgs-unstable 5.1.1 pkgs.matomo-beta A real-time web analytics application nixos-24.05 5.0.0-rc9 nixpkgs-24.05-darwin 5.0.0-rc9 nixos-24.05-small 5.0.0-rc9 nixos-24.11 5.0.0-rc9 nixpkgs-24.11-darwin 5.2.0-rc1 nixos-24.11-small 5.2.0-rc1 nixos-unstable 5.0.0-rc9 nixos-unstable-small 5.2.0-rc1 nixpkgs-unstable 5.0.0-rc9 Notify package maintainers: 12 @Kiwi Robert Djubek <envy1988@gmail.com> @leona-ya Leona Maroni <nix@leona.is> @sebbel Sebastian Ball <hej@sebastian-ball.de> @laalsaas laalsaas <laalsaas@systemli.org> @boozedog David A. Buser <code@booze.dog> @dpausp Tobias Stenzel <dpausp@posteo.de> @ctheune Christian Theune <ct@flyingcircus.io> @frlan Frank Lanitz <frank@frank.uvena.de> @osnyx Oliver Schmidt <os@flyingcircus.io> @Twey James ‘Twey’ Kay <twey@twey.co.uk> @florianjacob Florian Jacob <projects+nixos@florianjacob.de> @Ma27 Maximilian Bosch <maximilian@mbosch.me>
CVE-2024-7006 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 3 weeks ago Libtiff: null pointer dereference in tif_dirinfo.c A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service. libtiff * pkgs.libtiff Library and utilities for working with the TIFF image file format nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 4.7.0 nixpkgs-24.11-darwin 4.7.0 nixos-24.11-small 4.7.0 nixos-unstable 4.7.0 nixos-unstable-small 4.7.0 nixpkgs-unstable 4.7.0 pkgs.libtiff_t Library and utilities for working with the TIFF image file format (fork containing tools dropped in original libtiff version) nixos-24.05 4.6.0t nixpkgs-24.05-darwin 4.6.0t nixos-24.05-small 4.6.0t Notify package maintainers: 7 @nialov Nikolas Ovaskainen <nikolasovaskainen@gmail.com> @nh2 Niklas Hambüchen <mail@nh2.me> @imincik Ivan Mincik <ivan.mincik@gmail.com> @l0b0 Victor Engmark <victor@engmark.name> @willcohen Will Cohen @sikmir Nikolay Korotkiy <sikmir@disroot.org> @Yarny0 Yarny
pkgs.libtiff Library and utilities for working with the TIFF image file format nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 4.7.0 nixpkgs-24.11-darwin 4.7.0 nixos-24.11-small 4.7.0 nixos-unstable 4.7.0 nixos-unstable-small 4.7.0 nixpkgs-unstable 4.7.0
pkgs.libtiff_t Library and utilities for working with the TIFF image file format (fork containing tools dropped in original libtiff version) nixos-24.05 4.6.0t nixpkgs-24.05-darwin 4.6.0t nixos-24.05-small 4.6.0t
CVE-2022-47161 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 3 weeks ago WordPress Health Check & Troubleshooting Plugin <= 1.5.1 is vulnerable to Cross Site Request Forgery (CSRF) Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions. health-check =<1.5.1 pkgs.health-check Process monitoring tool nixos-24.05 0.04.00 nixpkgs-24.05-darwin 0.04.00 nixos-24.05-small 0.04.00 nixos-24.11 0.04.00 nixpkgs-24.11-darwin 0.04.00 nixos-24.11-small 0.04.00 nixos-unstable 0.04.00 nixos-unstable-small 0.04.00 nixpkgs-unstable 0.04.00 pkgs.grpc-health-check Minimal, high performance, memory-friendly, safe implementation of the gRPC health checking protocol nixos-24.11 2022-08-19 nixpkgs-24.11-darwin 2022-08-19 nixos-24.11-small 2022-08-19 nixos-unstable 2022-08-19 nixos-unstable-small 2022-08-19 nixpkgs-unstable 2022-08-19 pkgs.python311Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-24.05 3.18.1 nixpkgs-24.05-darwin 3.18.1 nixos-24.05-small 3.18.1 nixos-24.11 3.18.3 nixpkgs-24.11-darwin 3.18.3 nixos-24.11-small 3.18.3 nixos-unstable 3.18.3 nixos-unstable-small 3.18.3 nixpkgs-unstable 3.18.3 pkgs.python312Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-24.05 3.18.1 nixpkgs-24.05-darwin 3.18.1 nixos-24.05-small 3.18.1 nixos-24.11 3.18.3 nixpkgs-24.11-darwin 3.18.3 nixos-24.11-small 3.18.3 nixos-unstable 3.18.3 nixos-unstable-small 3.18.3 nixpkgs-unstable 3.18.3 pkgs.rubyPackages.github-pages-health-check nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 pkgs.python311Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-24.05 1.62.2 nixpkgs-24.05-darwin 1.62.2 nixos-24.05-small 1.62.2 nixos-24.11 1.67.0 nixpkgs-24.11-darwin 1.67.0 nixos-24.11-small 1.67.0 nixos-unstable 1.67.0 nixos-unstable-small 1.67.0 nixpkgs-unstable 1.67.0 pkgs.python312Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-24.05 1.62.2 nixpkgs-24.05-darwin 1.62.2 nixos-24.05-small 1.62.2 nixos-24.11 1.67.0 nixpkgs-24.11-darwin 1.67.0 nixos-24.11-small 1.67.0 nixos-unstable 1.67.0 nixos-unstable-small 1.67.0 nixpkgs-unstable 1.67.0 pkgs.rubyPackages_3_1.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2 pkgs.rubyPackages_3_2.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2 pkgs.rubyPackages_3_3.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2 pkgs.rubyPackages_3_4.github-pages-health-check nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2 Notify package maintainers: 4 @dtzWill Will Dietz <w@wdtz.org> @flokli Florian Klink <flokli@flokli.de> @onny Jonas Heinrich <onny@project-insanity.org> @happysalada Raphael Megzari <raphael@megzari.com>
pkgs.health-check Process monitoring tool nixos-24.05 0.04.00 nixpkgs-24.05-darwin 0.04.00 nixos-24.05-small 0.04.00 nixos-24.11 0.04.00 nixpkgs-24.11-darwin 0.04.00 nixos-24.11-small 0.04.00 nixos-unstable 0.04.00 nixos-unstable-small 0.04.00 nixpkgs-unstable 0.04.00
pkgs.grpc-health-check Minimal, high performance, memory-friendly, safe implementation of the gRPC health checking protocol nixos-24.11 2022-08-19 nixpkgs-24.11-darwin 2022-08-19 nixos-24.11-small 2022-08-19 nixos-unstable 2022-08-19 nixos-unstable-small 2022-08-19 nixpkgs-unstable 2022-08-19
pkgs.python311Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-24.05 3.18.1 nixpkgs-24.05-darwin 3.18.1 nixos-24.05-small 3.18.1 nixos-24.11 3.18.3 nixpkgs-24.11-darwin 3.18.3 nixos-24.11-small 3.18.3 nixos-unstable 3.18.3 nixos-unstable-small 3.18.3 nixpkgs-unstable 3.18.3
pkgs.python312Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-24.05 3.18.1 nixpkgs-24.05-darwin 3.18.1 nixos-24.05-small 3.18.1 nixos-24.11 3.18.3 nixpkgs-24.11-darwin 3.18.3 nixos-24.11-small 3.18.3 nixos-unstable 3.18.3 nixos-unstable-small 3.18.3 nixpkgs-unstable 3.18.3
pkgs.python311Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-24.05 1.62.2 nixpkgs-24.05-darwin 1.62.2 nixos-24.05-small 1.62.2 nixos-24.11 1.67.0 nixpkgs-24.11-darwin 1.67.0 nixos-24.11-small 1.67.0 nixos-unstable 1.67.0 nixos-unstable-small 1.67.0 nixpkgs-unstable 1.67.0
pkgs.python312Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-24.05 1.62.2 nixpkgs-24.05-darwin 1.62.2 nixos-24.05-small 1.62.2 nixos-24.11 1.67.0 nixpkgs-24.11-darwin 1.67.0 nixos-24.11-small 1.67.0 nixos-unstable 1.67.0 nixos-unstable-small 1.67.0 nixpkgs-unstable 1.67.0
pkgs.rubyPackages_3_1.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2
pkgs.rubyPackages_3_2.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2
pkgs.rubyPackages_3_3.github-pages-health-check nixos-24.05 1.18.2 nixpkgs-24.05-darwin 1.18.2 nixos-24.05-small 1.18.2 nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2
pkgs.rubyPackages_3_4.github-pages-health-check nixos-24.11 1.18.2 nixpkgs-24.11-darwin 1.18.2 nixos-24.11-small 1.18.2 nixos-unstable 1.18.2 nixos-unstable-small 1.18.2 nixpkgs-unstable 1.18.2
CVE-2023-32550 9.3 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 3 weeks ago Landscape's Apache server-status is accessible by default Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API. landscape <19.10.05 pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Notify package maintainers: 3 @manveru Michael Fellinger <m.fellinger@gmail.com> @mbode Maximilian Bode <maxbode@gmail.com> @nicknovitski Nick Novitski <nixpkgs@nicknovitski.com>
pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1
pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
CVE-2023-32549 6.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 2 months, 3 weeks ago Landscape insecure token generation Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator. landscape <19.10.05 pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Notify package maintainers: 3 @manveru Michael Fellinger <m.fellinger@gmail.com> @mbode Maximilian Bode <maxbode@gmail.com> @nicknovitski Nick Novitski <nixpkgs@nicknovitski.com>
pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1
pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
CVE-2023-32551 6.1 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 2 months, 3 weeks ago Landscape Open Redirect Landscape allowed URLs which caused open redirection. landscape <19.10.05 pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Notify package maintainers: 3 @manveru Michael Fellinger <m.fellinger@gmail.com> @mbode Maximilian Bode <maxbode@gmail.com> @nicknovitski Nick Novitski <nixpkgs@nicknovitski.com>
pkgs.terraform-landscape Improve Terraform's plan output to be easier to read and understand nixos-24.05 0.2.1 nixpkgs-24.05-darwin 0.2.1 nixos-24.05-small 0.2.1 nixos-24.11 0.2.1 nixpkgs-24.11-darwin 0.2.1 nixos-24.11-small 0.2.1 nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1
pkgs.ue4demos.landscape_mountains Unreal Engine 4 Linux demos nixos-24.05 ??? nixpkgs-24.05-darwin nixos-24.05-small nixos-24.11 ??? nixpkgs-24.11-darwin nixos-24.11-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
CVE-2023-6277 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 4 weeks ago Libtiff: out-of-memory in tiffopen via a craft file An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB. iv tkimg libtiff mingw-libtiff compat-libtiff3 pkgs.libtiff Library and utilities for working with the TIFF image file format nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 4.7.0 nixpkgs-24.11-darwin 4.7.0 nixos-24.11-small 4.7.0 nixos-unstable 4.7.0 nixos-unstable-small 4.7.0 nixpkgs-unstable 4.7.0 pkgs.libtiff_t Library and utilities for working with the TIFF image file format (fork containing tools dropped in original libtiff version) nixos-24.05 4.6.0t nixpkgs-24.05-darwin 4.6.0t nixos-24.05-small 4.6.0t Notify package maintainers: 8 @l0b0 Victor Engmark <victor@engmark.name> @autra Augustin Trancart <augustin.trancart@gmail.com> @willcohen Will Cohen @nialov Nikolas Ovaskainen <nikolasovaskainen@gmail.com> @nh2 Niklas Hambüchen <mail@nh2.me> @sikmir Nikolay Korotkiy <sikmir@disroot.org> @imincik Ivan Mincik <ivan.mincik@gmail.com> @Yarny0 Yarny
pkgs.libtiff Library and utilities for working with the TIFF image file format nixos-24.05 4.6.0 nixpkgs-24.05-darwin 4.6.0 nixos-24.05-small 4.6.0 nixos-24.11 4.7.0 nixpkgs-24.11-darwin 4.7.0 nixos-24.11-small 4.7.0 nixos-unstable 4.7.0 nixos-unstable-small 4.7.0 nixpkgs-unstable 4.7.0
pkgs.libtiff_t Library and utilities for working with the TIFF image file format (fork containing tools dropped in original libtiff version) nixos-24.05 4.6.0t nixpkgs-24.05-darwin 4.6.0t nixos-24.05-small 4.6.0t
CVE-2023-6596 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 2 months, 4 weeks ago Openshift: incomplete fix for rapid reset (cve-2023-44487/cve-2023-39325) An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers. openshift <4.12.48 <4.11.58 openshift4/ose-olm-rukpak-rhel8 openshift4/ose-operator-lifecycle-manager * pkgs.openshift Build, deploy, and manage your applications with Docker and Kubernetes nixos-24.05 4.14.0 nixpkgs-24.05-darwin 4.14.0 nixos-24.05-small 4.14.0 nixos-24.11 4.16.0 nixpkgs-24.11-darwin 4.16.0 nixos-24.11-small 4.16.0 nixos-unstable 4.16.0 nixos-unstable-small 4.16.0 nixpkgs-unstable 4.16.0 pkgs.python311Packages.openshift Python client for the OpenShift API nixos-24.05 0.13.2 nixpkgs-24.05-darwin 0.13.2 nixos-24.05-small 0.13.2 nixos-24.11 0.13.2 nixpkgs-24.11-darwin 0.13.2 nixos-24.11-small 0.13.2 nixos-unstable 0.13.2 nixos-unstable-small 0.13.2 nixpkgs-unstable 0.13.2 pkgs.python312Packages.openshift Python client for the OpenShift API nixos-24.05 0.13.2 nixpkgs-24.05-darwin 0.13.2 nixos-24.05-small 0.13.2 nixos-24.11 0.13.2 nixpkgs-24.11-darwin 0.13.2 nixos-24.11-small 0.13.2 nixos-unstable 0.13.2 nixos-unstable-small 0.13.2 nixpkgs-unstable 0.13.2 pkgs.python311Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0 pkgs.python312Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0 Notify package maintainers: 4 @stehessel Stephan Heßelmann <stephan@stehessel.de> @moretea Maarten Hoogendoorn <maarten@moretea.nl> @offlinehacker Jaka Hudoklin <jaka@x-truder.net> @teto Matthieu Coudron <mcoudron@hotmail.com>
pkgs.openshift Build, deploy, and manage your applications with Docker and Kubernetes nixos-24.05 4.14.0 nixpkgs-24.05-darwin 4.14.0 nixos-24.05-small 4.14.0 nixos-24.11 4.16.0 nixpkgs-24.11-darwin 4.16.0 nixos-24.11-small 4.16.0 nixos-unstable 4.16.0 nixos-unstable-small 4.16.0 nixpkgs-unstable 4.16.0
pkgs.python311Packages.openshift Python client for the OpenShift API nixos-24.05 0.13.2 nixpkgs-24.05-darwin 0.13.2 nixos-24.05-small 0.13.2 nixos-24.11 0.13.2 nixpkgs-24.11-darwin 0.13.2 nixos-24.11-small 0.13.2 nixos-unstable 0.13.2 nixos-unstable-small 0.13.2 nixpkgs-unstable 0.13.2
pkgs.python312Packages.openshift Python client for the OpenShift API nixos-24.05 0.13.2 nixpkgs-24.05-darwin 0.13.2 nixos-24.05-small 0.13.2 nixos-24.11 0.13.2 nixpkgs-24.11-darwin 0.13.2 nixos-24.11-small 0.13.2 nixos-unstable 0.13.2 nixos-unstable-small 0.13.2 nixpkgs-unstable 0.13.2
pkgs.python311Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0
pkgs.python312Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0
CVE-2024-45617 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized. opensc libopensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-24.05 0.26.0 nixpkgs-24.05-darwin 0.26.0 nixos-24.05-small 0.26.0 nixos-24.11 0.26.0 nixpkgs-24.11-darwin 0.26.0 nixos-24.11-small 0.26.0 nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0 pkgs.openscad 3D parametric model compiler nixos-24.05 2021.01 nixpkgs-24.05-darwin 2021.01 nixos-24.05-small 2021.01 nixos-24.11 2021.01 nixpkgs-24.11-darwin 2021.01 nixos-24.11-small 2021.01 nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-24.11 1.3.10 nixpkgs-24.11-darwin 1.3.10 nixos-24.11-small 1.3.10 nixos-unstable 1.3.10 nixos-unstable-small 1.3.10 nixpkgs-unstable 1.3.10 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-24.05 1.2.5 nixpkgs-24.05-darwin 1.2.5 nixos-24.05-small 1.2.5 nixos-24.11 1.2.5 nixpkgs-24.11-darwin 1.2.5 nixos-24.11-small 1.2.5 nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5 pkgs.openscenegraph 3D graphics toolkit nixos-24.05 3.6.5 nixpkgs-24.05-darwin 3.6.5 nixos-24.05-small 3.6.5 nixos-24.11 3.6.5 nixpkgs-24.11-darwin 3.6.5 nixos-24.11-small 3.6.5 nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-24.05 2024-03-10 nixpkgs-24.05-darwin 2024-03-10 nixos-24.05-small 2024-03-10 nixos-24.11 2024-11-10 nixpkgs-24.11-darwin 2024-11-10 nixos-24.11-small 2024-11-10 nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06 pkgs.vimPlugins.vim-openscad nixos-24.05 2022-07-26 nixpkgs-24.05-darwin 2022-07-26 nixos-24.05-small 2022-07-26 nixos-24.11 2022-07-26 nixpkgs-24.11-darwin 2022-07-26 nixos-24.11-small 2022-07-26 nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26 pkgs.vimPlugins.openscad-nvim nixos-24.05 2024-04-13 nixpkgs-24.05-darwin 2024-04-13 nixos-24.05-small 2024-04-13 nixos-24.11 2024-04-13 nixpkgs-24.11-darwin 2024-04-13 nixos-24.11-small 2024-04-13 nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13 pkgs.kakounePlugins.openscad-kak nixos-24.05 2020-12-10 nixpkgs-24.05-darwin 2020-12-10 nixos-24.05-small 2020-12-10 nixos-24.11 2020-12-10 nixpkgs-24.11-darwin 2020-12-10 nixos-24.11-small 2020-12-10 nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-24.05 1.1.1 nixpkgs-24.05-darwin 1.1.1 nixos-24.05-small 1.1.1 nixos-24.11 1.3.1 nixpkgs-24.11-darwin 1.3.1 nixos-24.11-small 1.3.1 nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1 Notify package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @gebner Gabriel Ebner <gebner@gebner.org> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @aanderse Aaron Andersen <aaron@fosslib.net> @pca006132 pca006132 <john.lck40@gmail.com>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-24.05 0.26.0 nixpkgs-24.05-darwin 0.26.0 nixos-24.05-small 0.26.0 nixos-24.11 0.26.0 nixpkgs-24.11-darwin 0.26.0 nixos-24.11-small 0.26.0 nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0
pkgs.openscad 3D parametric model compiler nixos-24.05 2021.01 nixpkgs-24.05-darwin 2021.01 nixos-24.05-small 2021.01 nixos-24.11 2021.01 nixpkgs-24.11-darwin 2021.01 nixos-24.11-small 2021.01 nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01
pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-24.11 1.3.10 nixpkgs-24.11-darwin 1.3.10 nixos-24.11-small 1.3.10 nixos-unstable 1.3.10 nixos-unstable-small 1.3.10 nixpkgs-unstable 1.3.10
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-24.05 1.2.5 nixpkgs-24.05-darwin 1.2.5 nixos-24.05-small 1.2.5 nixos-24.11 1.2.5 nixpkgs-24.11-darwin 1.2.5 nixos-24.11-small 1.2.5 nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5
pkgs.openscenegraph 3D graphics toolkit nixos-24.05 3.6.5 nixpkgs-24.05-darwin 3.6.5 nixos-24.05-small 3.6.5 nixos-24.11 3.6.5 nixpkgs-24.11-darwin 3.6.5 nixos-24.11-small 3.6.5 nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-24.05 2024-03-10 nixpkgs-24.05-darwin 2024-03-10 nixos-24.05-small 2024-03-10 nixos-24.11 2024-11-10 nixpkgs-24.11-darwin 2024-11-10 nixos-24.11-small 2024-11-10 nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06
pkgs.vimPlugins.vim-openscad nixos-24.05 2022-07-26 nixpkgs-24.05-darwin 2022-07-26 nixos-24.05-small 2022-07-26 nixos-24.11 2022-07-26 nixpkgs-24.11-darwin 2022-07-26 nixos-24.11-small 2022-07-26 nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26
pkgs.vimPlugins.openscad-nvim nixos-24.05 2024-04-13 nixpkgs-24.05-darwin 2024-04-13 nixos-24.05-small 2024-04-13 nixos-24.11 2024-04-13 nixpkgs-24.11-darwin 2024-04-13 nixos-24.11-small 2024-04-13 nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13
pkgs.kakounePlugins.openscad-kak nixos-24.05 2020-12-10 nixpkgs-24.05-darwin 2020-12-10 nixos-24.05-small 2020-12-10 nixos-24.11 2020-12-10 nixpkgs-24.11-darwin 2020-12-10 nixos-24.11-small 2020-12-10 nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-24.05 1.1.1 nixpkgs-24.05-darwin 1.1.1 nixos-24.05-small 1.1.1 nixos-24.11 1.3.1 nixpkgs-24.11-darwin 1.3.1 nixos-24.11-small 1.3.1 nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1
CVE-2024-38789 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago WordPress Telegram Bot & Channel plugin <= 3.8.2 - Cross Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Telegram Bot & Channel allows Cross Site Request Forgery.This issue affects Telegram Bot & Channel: from n/a through 3.8.2. telegram-bot =<3.8.2 pkgs.telegram-bot-api Telegram Bot API server nixos-24.05 7.3 nixpkgs-24.05-darwin 7.3 nixos-24.05-small 7.3 nixos-24.11 7.11 nixpkgs-24.11-darwin 7.11 nixos-24.11-small 7.11 nixos-unstable 8.0 nixos-unstable-small 8.0 nixpkgs-unstable 8.0 pkgs.haskellPackages.telegram-bot-api Easy to use library for building Telegram bots. Exports Telegram Bot API. nixos-24.05 7.0 nixpkgs-24.05-darwin 7.0 nixos-24.05-small 7.0 nixos-24.11 7.4.1 nixpkgs-24.11-darwin 7.4.1 nixos-24.11-small 7.4.1 nixos-unstable 7.4.1 nixos-unstable-small 7.4.1 nixpkgs-unstable 7.4.1 pkgs.haskellPackages.telegram-bot-simple Easy to use library for building Telegram bots nixos-24.05 0.13 nixpkgs-24.05-darwin 0.13 nixos-24.05-small 0.13 nixos-24.11 0.14.3 nixpkgs-24.11-darwin 0.14.3 nixos-24.11-small 0.14.3 nixos-unstable 0.14.3 nixos-unstable-small 0.14.3 nixpkgs-unstable 0.14.3 pkgs.python311Packages.python-telegram-bot Python library to interface with the Telegram Bot API nixos-24.05 21.2 nixpkgs-24.05-darwin 21.2 nixos-24.05-small 21.2 nixos-24.11 21.7 nixpkgs-24.11-darwin 21.7 nixos-24.11-small 21.7 nixos-unstable 21.7 nixos-unstable-small 21.7 nixpkgs-unstable 21.7 pkgs.python312Packages.python-telegram-bot Python library to interface with the Telegram Bot API nixos-24.05 21.2 nixpkgs-24.05-darwin 21.2 nixos-24.05-small 21.2 nixos-24.11 21.7 nixpkgs-24.11-darwin 21.7 nixos-24.11-small 21.7 nixos-unstable 21.7 nixos-unstable-small 21.7 nixpkgs-unstable 21.7 Notify package maintainers: 4 @Anillc Anillc <i@anillc.cn> @Forden Forden <forden@zuku.tech> @veprbl Dmitry Kalinkin <veprbl@gmail.com> @pingiun Jelle Besseling <nixos@pingiun.com>
pkgs.telegram-bot-api Telegram Bot API server nixos-24.05 7.3 nixpkgs-24.05-darwin 7.3 nixos-24.05-small 7.3 nixos-24.11 7.11 nixpkgs-24.11-darwin 7.11 nixos-24.11-small 7.11 nixos-unstable 8.0 nixos-unstable-small 8.0 nixpkgs-unstable 8.0
pkgs.haskellPackages.telegram-bot-api Easy to use library for building Telegram bots. Exports Telegram Bot API. nixos-24.05 7.0 nixpkgs-24.05-darwin 7.0 nixos-24.05-small 7.0 nixos-24.11 7.4.1 nixpkgs-24.11-darwin 7.4.1 nixos-24.11-small 7.4.1 nixos-unstable 7.4.1 nixos-unstable-small 7.4.1 nixpkgs-unstable 7.4.1
pkgs.haskellPackages.telegram-bot-simple Easy to use library for building Telegram bots nixos-24.05 0.13 nixpkgs-24.05-darwin 0.13 nixos-24.05-small 0.13 nixos-24.11 0.14.3 nixpkgs-24.11-darwin 0.14.3 nixos-24.11-small 0.14.3 nixos-unstable 0.14.3 nixos-unstable-small 0.14.3 nixpkgs-unstable 0.14.3
pkgs.python311Packages.python-telegram-bot Python library to interface with the Telegram Bot API nixos-24.05 21.2 nixpkgs-24.05-darwin 21.2 nixos-24.05-small 21.2 nixos-24.11 21.7 nixpkgs-24.11-darwin 21.7 nixos-24.11-small 21.7 nixos-unstable 21.7 nixos-unstable-small 21.7 nixpkgs-unstable 21.7
pkgs.python312Packages.python-telegram-bot Python library to interface with the Telegram Bot API nixos-24.05 21.2 nixpkgs-24.05-darwin 21.2 nixos-24.05-small 21.2 nixos-24.11 21.7 nixpkgs-24.11-darwin 21.7 nixos-24.11-small 21.7 nixos-unstable 21.7 nixos-unstable-small 21.7 nixpkgs-unstable 21.7
CVE-2024-38766 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago WordPress Matomo Analytics plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) leading to Notice Dismissal vulnerability Cross-Site Request Forgery (CSRF) vulnerability in Matomo Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from n/a through 5.1.1. matomo =<5.1.1 pkgs.matomo A real-time web analytics application nixos-24.05 4.16.1 nixpkgs-24.05-darwin 4.16.1 nixos-24.05-small 4.16.1 nixos-24.11 4.16.1 nixpkgs-24.11-darwin 4.16.1 nixos-24.11-small 4.16.1 nixos-unstable 4.16.1 nixos-unstable-small 4.16.1 nixpkgs-unstable 4.16.1 pkgs.matomo_5 Real-time web analytics application nixos-24.05 5.1.1 nixpkgs-24.05-darwin 5.1.1 nixos-24.05-small 5.1.1 nixos-24.11 5.1.1 nixpkgs-24.11-darwin 5.1.2 nixos-24.11-small 5.1.2 nixos-unstable 5.1.1 nixos-unstable-small 5.1.2 nixpkgs-unstable 5.1.1 pkgs.matomo-beta A real-time web analytics application nixos-24.05 5.0.0-rc9 nixpkgs-24.05-darwin 5.0.0-rc9 nixos-24.05-small 5.0.0-rc9 nixos-24.11 5.0.0-rc9 nixpkgs-24.11-darwin 5.2.0-rc1 nixos-24.11-small 5.2.0-rc1 nixos-unstable 5.0.0-rc9 nixos-unstable-small 5.2.0-rc1 nixpkgs-unstable 5.0.0-rc9 Notify package maintainers: 12 @Kiwi Robert Djubek <envy1988@gmail.com> @leona-ya Leona Maroni <nix@leona.is> @sebbel Sebastian Ball <hej@sebastian-ball.de> @laalsaas laalsaas <laalsaas@systemli.org> @boozedog David A. Buser <code@booze.dog> @dpausp Tobias Stenzel <dpausp@posteo.de> @ctheune Christian Theune <ct@flyingcircus.io> @frlan Frank Lanitz <frank@frank.uvena.de> @osnyx Oliver Schmidt <os@flyingcircus.io> @Twey James ‘Twey’ Kay <twey@twey.co.uk> @florianjacob Florian Jacob <projects+nixos@florianjacob.de> @Ma27 Maximilian Bosch <maximilian@mbosch.me>
pkgs.matomo A real-time web analytics application nixos-24.05 4.16.1 nixpkgs-24.05-darwin 4.16.1 nixos-24.05-small 4.16.1 nixos-24.11 4.16.1 nixpkgs-24.11-darwin 4.16.1 nixos-24.11-small 4.16.1 nixos-unstable 4.16.1 nixos-unstable-small 4.16.1 nixpkgs-unstable 4.16.1
pkgs.matomo_5 Real-time web analytics application nixos-24.05 5.1.1 nixpkgs-24.05-darwin 5.1.1 nixos-24.05-small 5.1.1 nixos-24.11 5.1.1 nixpkgs-24.11-darwin 5.1.2 nixos-24.11-small 5.1.2 nixos-unstable 5.1.1 nixos-unstable-small 5.1.2 nixpkgs-unstable 5.1.1
pkgs.matomo-beta A real-time web analytics application nixos-24.05 5.0.0-rc9 nixpkgs-24.05-darwin 5.0.0-rc9 nixos-24.05-small 5.0.0-rc9 nixos-24.11 5.0.0-rc9 nixpkgs-24.11-darwin 5.2.0-rc1 nixos-24.11-small 5.2.0-rc1 nixos-unstable 5.0.0-rc9 nixos-unstable-small 5.2.0-rc1 nixpkgs-unstable 5.0.0-rc9