Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created 4 months ago
WordPress Progress Tracker plugin <= 0.9.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Furr and Simon Ward Progress Tracker allows DOM-Based XSS.This issue affects Progress Tracker: from n/a through 0.9.3.

Affected products

progress-tracker
  • =<0.9.3

Matching in nixpkgs

pkgs.progress-tracker

Simple kanban-style task organiser

  • nixos-unstable -

Package maintainers: 1

created 4 months ago
WordPress Annie plugin <= 2.1.1 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Chris Roberts Annie allows Cross Site Request Forgery.This issue affects Annie: from n/a through 2.1.1.

Affected products

annie
  • =<2.1.1

Matching in nixpkgs

pkgs.wannier90

Calculation of maximally localised Wannier functions

  • nixos-unstable -

Package maintainers: 1

created 4 months ago
WordPress Slides & Presentations Plugin <= 0.0.39 - Content Injection vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Ella van Durpe Slides & Presentations allows Code Injection.This issue affects Slides & Presentations: from n/a through 0.0.39.

Affected products

slide
  • =<0.0.39

Matching in nixpkgs

pkgs.slides

Terminal based presentation tool

  • nixos-unstable -

pkgs.openslide

C library that provides a simple interface to read whole-slide images

  • nixos-unstable -

pkgs.manim-slides

Tool for live presentations using manim

  • nixos-unstable -

pkgs.dvd-slideshow

Suite of command line programs that creates a slideshow-style video from groups of pictures

pkgs.gnomeExtensions.backslide

Automatic background-image (wallpaper) slideshow for Gnome Shell

  • nixos-unstable -
    • nixpkgs-unstable 33

pkgs.python312Packages.openslide

Python bindings to the OpenSlide library for reading whole-slide microscopy images

  • nixos-unstable -

pkgs.python313Packages.openslide

Python bindings to the OpenSlide library for reading whole-slide microscopy images

  • nixos-unstable -

pkgs.haskellPackages.gogol-slides

Google Slides SDK

  • nixos-unstable -

pkgs.python312Packages.goslide-api

Python API to utilise the Slide Open Cloud and Local API

  • nixos-unstable -

pkgs.python313Packages.goslide-api

Python API to utilise the Slide Open Cloud and Local API

  • nixos-unstable -

pkgs.typstPackages.gradslide_0_1_0

Simple component to show a value between 0 and 1 on a nice gradient slider

  • nixos-unstable -

pkgs.typstPackages.typslides_1_1_1

Minimalistic Typst slides

  • nixos-unstable -

pkgs.typstPackages.typslides_1_2_0

Minimalistic Typst slides

  • nixos-unstable -

pkgs.typstPackages.typslides_1_2_1

Minimalistic Typst slides

  • nixos-unstable -

pkgs.typstPackages.typslides_1_2_3

Minimalistic Typst slides

  • nixos-unstable -

pkgs.typstPackages.typslides_1_2_4

Minimalistic Typst slides

  • nixos-unstable -

pkgs.typstPackages.typslides_1_2_5

Minimalistic Typst slides

  • nixos-unstable -

pkgs.typstPackages.typslides_1_2_6

Minimalistic Typst slides

  • nixos-unstable -

pkgs.python312Packages.manim-slides

Tool for live presentations using manim

  • nixos-unstable -

pkgs.python313Packages.manim-slides

Tool for live presentations using manim

  • nixos-unstable -

pkgs.vscode-extensions.antfu.slidev

  • nixos-unstable -

pkgs.python312Packages.textual-slider

Textual widget for a simple slider

  • nixos-unstable -

pkgs.python313Packages.textual-slider

Textual widget for a simple slider

  • nixos-unstable -

pkgs.typstPackages.parcio-slides_0_1_0

A simple polylux slide templated based on the ParCIO working group at OvGU Magdeburg

  • nixos-unstable -

pkgs.typstPackages.parcio-slides_0_1_1

A simple polylux slide templated based on the ParCIO working group at OvGU Magdeburg

  • nixos-unstable -

pkgs.gnomeExtensions.night-light-slider

Add a slider for Night Light temperature to the Quick Settings menu.

  • nixos-unstable -
    • nixpkgs-unstable 1

pkgs.gnomeExtensions.wallpaper-slideshow

Wallpaper slideshow extension. Optionally downloads BING wallpaper of the day.

  • nixos-unstable -
    • nixpkgs-unstable 13

pkgs.typstPackages.silky-slides-insa_0_1_0

A template made for presentations of INSA, a French engineering school

  • nixos-unstable -

pkgs.typstPackages.silky-slides-insa_0_1_1

A template made for presentations of INSA, a French engineering school

  • nixos-unstable -

pkgs.gnomeExtensions.keyboard-backlight-slider

Allow setting the keyboard backlight brightness with a slider in the main menu

  • nixos-unstable -
    • nixpkgs-unstable 6

pkgs.gnomeExtensions.night-light-slider-updated

Kiyui's Night Light Slider updated for GNOME 45. Provides a slider in the quick settings menu to control the night light temperature. Some nice options can be set in the extension preferences menu. Original implementation: https://codeberg.org/kiyui/gnome-shell-night-light-slider-extension/

  • nixos-unstable -
    • nixpkgs-unstable 13

pkgs.home-assistant-component-tests.slide_local

Open source home automation that puts local control and privacy first

pkgs.typstPackages.tud-corporate-design-slides_0_1_0

Presentation template for TU Dresden (Technische Universität Dresden

  • nixos-unstable -

pkgs.typstPackages.upb-corporate-design-slides_0_1_0

Presentation template for Paderborn University (UPB

  • nixos-unstable -

pkgs.typstPackages.upb-corporate-design-slides_0_1_1

Presentation template for Paderborn University (UPB

  • nixos-unstable -

pkgs.typstPackages.upb-corporate-design-slides_0_1_2

Presentation template for Paderborn University (UPB

  • nixos-unstable -

pkgs.typstPackages.upb-corporate-design-slides_0_1_3

Presentation template for Paderborn University (UPB

  • nixos-unstable -

pkgs.vscode-extensions.ms-toolsai.vscode-jupyter-slideshow

  • nixos-unstable -

Package maintainers: 13

created 4 months ago
WordPress Annie plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Roberts Annie allows Stored XSS.This issue affects Annie: from n/a through 2.1.1.

Affected products

annie
  • =<2.1.1

Matching in nixpkgs

pkgs.wannier90

Calculation of maximally localised Wannier functions

  • nixos-unstable -

Package maintainers: 1

created 4 months ago
WordPress Chatter plugin <= 1.0.1 - CSRF to Stored XSS vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Volkov Chatter allows Stored XSS. This issue affects Chatter: from n/a through 1.0.1.

Affected products

chatter
  • =<1.0.1

Matching in nixpkgs

pkgs.chatterino2

Chat client for Twitch chat

  • nixos-unstable -

pkgs.chatterino7

Chat client for Twitch chat

  • nixos-unstable -

pkgs.haskellPackages.chatter

A library of simple NLP algorithms

pkgs.typstPackages.chatter_0_1_0

Write dialog between any number of characters quickly and cleanly. Great for translations or short assignments

  • nixos-unstable -

Package maintainers: 4

created 4 months ago
Freeipa: administrative user data leaked through systemd journal

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-case scenario, where the journal log is centralized, users with access to it can have improper access to the FreeIPA administrator credentials.

Affected products

ipa
  • *
freeipa
  • ==4.12.2
idm:DL1/ipa
idm:client/ipa

Matching in nixpkgs

pkgs.ipam

Cli based IPAM written in Go with PowerDNS support

pkgs.tipa

Phonetic font for TeX

  • nixos-unstable -

pkgs.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.freeipa

Identity, Policy and Audit system

  • nixos-unstable -

pkgs.ipafont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.ipatool

Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

  • nixos-unstable -

pkgs.codipack

Fast gradient evaluation in C++ based on Expression Templates

  • nixos-unstable -

pkgs.snipaste

Screenshot tools

  • nixos-unstable -

pkgs.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.iniparser

Free standalone ini file parsing library

  • nixos-unstable -

pkgs.ipaexfont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.multipass

Ubuntu VMs on demand for any workstation

  • nixos-unstable -

pkgs.nipap-cli

Neat IP Address Planner CLI

  • nixos-unstable -

pkgs.nipap-www

Neat IP Address Planner CLI, web UI

  • nixos-unstable -

pkgs.uriparser

Strictly RFC 3986 compliant URI parsing library

  • nixos-unstable -

pkgs.frangipanni

Convert lines of text into a tree structure

  • nixos-unstable -

pkgs.ipad_charge

Apple device USB charging utility for Linux

pkgs.nucleiparser

Nuclei output parser for CLI

  • nixos-unstable -

pkgs.multipath-tools

Tools for the Linux multipathing storage driver

  • nixos-unstable -

pkgs.ripasso-cursive

Simple password manager written in Rust

  • nixos-unstable -

pkgs.multipart-parser-c

Http multipart parser implemented in C

pkgs.haskellPackages.ipa

Internal Phonetic Alphabet (IPA)

pkgs.python312Packages.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.python313Packages.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.python312Packages.ipaddr

IP address manipulation library

  • nixos-unstable -

pkgs.python312Packages.ipadic

Contemporary Written Japanese dictionary

  • nixos-unstable -

pkgs.python313Packages.ipaddr

IP address manipulation library

  • nixos-unstable -

pkgs.python313Packages.ipadic

Contemporary Written Japanese dictionary

  • nixos-unstable -

pkgs.haskellPackages.multipart

Parsers for the HTTP multipart format

  • nixos-unstable -

pkgs.python312Packages.pynipap

Python client library for Neat IP Address Planner

  • nixos-unstable -

pkgs.python313Packages.pynipap

Python client library for Neat IP Address Planner

  • nixos-unstable -

pkgs.python312Packages.iniparse

Accessing and Modifying INI files

  • nixos-unstable -

pkgs.python313Packages.iniparse

Accessing and Modifying INI files

  • nixos-unstable -

pkgs.graylogPlugins.ipanonymizer

Graylog-server plugin that replaces the last octet of IP addresses in messages with xxx

  • nixos-unstable -

pkgs.haskellPackages.unipatterns

Helpers which allow safe partial pattern matching in lambdas

pkgs.python312Packages.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.python312Packages.multipart

Parser for multipart/form-data

  • nixos-unstable -

pkgs.python313Packages.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.python313Packages.multipart

Parser for multipart/form-data

  • nixos-unstable -

pkgs.typstPackages.ascii-ipa_1_0_0

Converter for ASCII representations of the International Phonetic Alphabet (IPA

  • nixos-unstable -

pkgs.typstPackages.ascii-ipa_1_1_0

Converter for ASCII representations of the International Phonetic Alphabet (IPA

  • nixos-unstable -

pkgs.typstPackages.ascii-ipa_1_1_1

Converter for ASCII representations of the International Phonetic Alphabet (IPA

  • nixos-unstable -

pkgs.typstPackages.ascii-ipa_2_0_0

Converter for ASCII representations of the International Phonetic Alphabet (IPA

  • nixos-unstable -

pkgs.haskellPackages.multipart-names

Handling of multipart names in various casing styles

  • nixos-unstable -

pkgs.haskellPackages.servant-multipart

multipart/form-data (e.g file upload) support for servant

  • nixos-unstable -

pkgs.python312Packages.flask-principal

Identity management for flask

  • nixos-unstable -

pkgs.python312Packages.types-ipaddress

Typing stubs for ipaddress

  • nixos-unstable -

pkgs.python313Packages.flask-principal

Identity management for flask

  • nixos-unstable -

pkgs.python313Packages.types-ipaddress

Typing stubs for ipaddress

  • nixos-unstable -

pkgs.python312Packages.cached-ipaddress

Cache construction of ipaddress objects

  • nixos-unstable -

pkgs.python312Packages.python-multipart

Streaming multipart parser for Python

  • nixos-unstable -

pkgs.python312Packages.python-vipaccess

Free software implementation of Symantec's VIP Access application and protocol

  • nixos-unstable -

pkgs.python312Packages.sansio-multipart

Parser for multipart/form-data

  • nixos-unstable -

pkgs.python313Packages.cached-ipaddress

Cache construction of ipaddress objects

  • nixos-unstable -

pkgs.python313Packages.python-multipart

Streaming multipart parser for Python

  • nixos-unstable -

pkgs.python313Packages.python-vipaccess

Free software implementation of Symantec's VIP Access application and protocol

  • nixos-unstable -

pkgs.python313Packages.sansio-multipart

Parser for multipart/form-data

  • nixos-unstable -

pkgs.haskellPackages.http-client-multipart

Generate multipart uploads for http-client. (deprecated)

pkgs.haskellPackages.servant-multipart-api

multipart/form-data (e.g file upload) support for servant

  • nixos-unstable -

pkgs.haskellPackages.servant-multipart-client

multipart/form-data (e.g file upload) support for servant

  • nixos-unstable -

pkgs.python312Packages.nested-multipart-parser

Parser for nested data for 'multipart/form'

  • nixos-unstable -

pkgs.python313Packages.nested-multipart-parser

Parser for nested data for 'multipart/form'

  • nixos-unstable -

pkgs.haskellPackages.amazonka-connectparticipant

Amazon Connect Participant Service SDK

  • nixos-unstable -

pkgs.haskellPackages.autodocodec-servant-multipart

Autodocodec interpreters for Servant Multipart

pkgs.chickenPackages_5.chickenEggs.multipart-form-data

Reads & decodes HTTP multipart/form-data requests.

  • nixos-unstable -

pkgs.python312Packages.types-aiobotocore-connectparticipant

Type annotations for aiobotocore connectparticipant

  • nixos-unstable -

pkgs.python313Packages.types-aiobotocore-connectparticipant

Type annotations for aiobotocore connectparticipant

  • nixos-unstable -

pkgs.python312Packages.microsoft-kiota-serialization-multipart

Multipart serialization implementation for Kiota clients in Python

  • nixos-unstable -

pkgs.python313Packages.microsoft-kiota-serialization-multipart

Multipart serialization implementation for Kiota clients in Python

  • nixos-unstable -

Package maintainers: 24

created 4 months ago
WordPress Partners Plugin <= 0.2.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mighty Digital Partners allows Reflected XSS.This issue affects Partners: from n/a through 0.2.0.

Affected products

partners
  • =<0.2.0

Matching in nixpkgs

pkgs.haskellPackages.gogol-partners

Google Partners SDK

  • nixos-unstable -
created 4 months ago
Transmission of Private Resources into a New Sphere in Crafter Engine

Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.

Affected products

Engine
  • <4.0.8
  • <4.1.6

Matching in nixpkgs

pkgs.perlPackages.XMLXPathEngine

Re-usable XPath engine for DOM-like trees

  • nixos-unstable -

pkgs.perlPackages.ZonemasterEngine

Tool to check the quality of a DNS zone

  • nixos-unstable -

pkgs.haskellPackages.Control-Engine

A parallel producer/consumer engine (thread pool)

pkgs.perl538Packages.XMLXPathEngine

Re-usable XPath engine for DOM-like trees

  • nixos-unstable -

pkgs.perl540Packages.XMLXPathEngine

Re-usable XPath engine for DOM-like trees

  • nixos-unstable -

pkgs.perl538Packages.ZonemasterEngine

Tool to check the quality of a DNS zone

  • nixos-unstable -

pkgs.perl540Packages.ZonemasterEngine

Tool to check the quality of a DNS zone

  • nixos-unstable -
created 4 months ago
Rsync: heap buffer overflow in rsync due to improper checksum length handling

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

Affected products

rhcos
rsync
  • ==3.2.7
  • ==3.3.0
  • *

Matching in nixpkgs

pkgs.rsync

Fast incremental file transfer utility

  • nixos-unstable -

pkgs.grsync

Synchronize folders, files and make backups

  • nixos-unstable -

pkgs.rrsync

Helper to run rsync-only environments from ssh-logins

  • nixos-unstable -

pkgs.rsyncy

Progress bar wrapper for rsync

  • nixos-unstable -

pkgs.librsync

Implementation of the rsync remote-delta algorithm

  • nixos-unstable -

pkgs.diskrsync

Rsync for block devices and disk images

  • nixos-unstable -

pkgs.ethersync

Real-time co-editing of local text files

  • nixos-unstable -

pkgs.openrsync

BSD-licensed implementation of rsync

pkgs.sqlite-rsync

Database remote-copy tool for SQLite

  • nixos-unstable -

pkgs.vdirsyncerStable

Synchronize calendars and contacts

  • nixos-unstable -

pkgs.yaziPlugins.rsync

Simple rsync plugin for yazi file manager

pkgs.vimPlugins.ethersync

Real-time co-editing of local text files

  • nixos-unstable -

pkgs.python312Packages.sysrsync

Simple and safe system's rsync wrapper for Python

  • nixos-unstable -

pkgs.python313Packages.sysrsync

Simple and safe system's rsync wrapper for Python

  • nixos-unstable -

pkgs.python312Packages.vdirsyncer

Synchronize calendars and contacts

  • nixos-unstable -

pkgs.python313Packages.vdirsyncer

Synchronize calendars and contacts

  • nixos-unstable -

pkgs.vscode-extensions.ethersync.ethersync

Extension for real-time co-editing of local text files

  • nixos-unstable -

Package maintainers: 16

created 4 months ago
Rsync: rsync server leaks arbitrary client files

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.

Affected products

rhcos
rsync
  • =<3.3.0

Matching in nixpkgs

pkgs.rsync

Fast incremental file transfer utility

  • nixos-unstable -

pkgs.grsync

Synchronize folders, files and make backups

  • nixos-unstable -

pkgs.rrsync

Helper to run rsync-only environments from ssh-logins

  • nixos-unstable -

pkgs.rsyncy

Progress bar wrapper for rsync

  • nixos-unstable -

pkgs.librsync

Implementation of the rsync remote-delta algorithm

  • nixos-unstable -

pkgs.diskrsync

Rsync for block devices and disk images

  • nixos-unstable -

pkgs.ethersync

Real-time co-editing of local text files

  • nixos-unstable -

pkgs.openrsync

BSD-licensed implementation of rsync

pkgs.sqlite-rsync

Database remote-copy tool for SQLite

  • nixos-unstable -

pkgs.vdirsyncerStable

Synchronize calendars and contacts

  • nixos-unstable -

pkgs.yaziPlugins.rsync

Simple rsync plugin for yazi file manager

pkgs.vimPlugins.ethersync

Real-time co-editing of local text files

  • nixos-unstable -

pkgs.python312Packages.sysrsync

Simple and safe system's rsync wrapper for Python

  • nixos-unstable -

pkgs.python313Packages.sysrsync

Simple and safe system's rsync wrapper for Python

  • nixos-unstable -

pkgs.python312Packages.vdirsyncer

Synchronize calendars and contacts

  • nixos-unstable -

pkgs.python313Packages.vdirsyncer

Synchronize calendars and contacts

  • nixos-unstable -

pkgs.vscode-extensions.ethersync.ethersync

Extension for real-time co-editing of local text files

  • nixos-unstable -

Package maintainers: 16