⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2023-45348 created 6 months, 2 weeks ago
Apache Airflow: Configuration information leakage vulnerability

Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recommended to upgrade to a version that is not affected.

apache-airflow
<2.7.2

pkgs.apache-airflow

Programmatically author, schedule and monitor data pipelines
Package maintainers: 3
CVE-2023-5366
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 6 months, 2 weeks ago
Openvswitch don't match packets on nd_target field

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

openvswitch
openvswitch3.0
openvswitch3.1
openvswitch2.10
openvswitch2.11
openvswitch2.12
openvswitch2.13
openvswitch2.15
openvswitch2.16
openvswitch2.17
rhosp-openvswitch
openvswitch-ovn-kubernetes
redhat-virtualization-host

pkgs.openvswitch

Multilayer virtual switch

pkgs.openvswitch-dpdk

Multilayer virtual switch
Package maintainers: 4
CVE-2023-4255
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 6 months, 2 weeks ago
W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)

An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.

w3m
Package maintainers: 1
CVE-2024-27906
5.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 6 months, 2 weeks ago
Apache Airflow: Dag Code and Import Error Permissions Ignored

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability

apache-airflow
<2.8.2

pkgs.apache-airflow

Programmatically author, schedule and monitor data pipelines
Package maintainers: 3
CVE-2023-42663 created 6 months, 2 weeks ago
Apache Airflow: Bypass permission verification to view task instances of other dags

Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

apache-airflow
<2.7.2

pkgs.apache-airflow

Programmatically author, schedule and monitor data pipelines
Package maintainers: 3
CVE-2023-4136
7.4 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 6 months, 2 weeks ago
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafter Engine

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.

Engine
=<3.1.27
=<4.0.2

pkgs.haskellPackages.Control-Engine

A parallel producer/consumer engine (thread pool)

pkgs.perl538Packages.XMLXPathEngine

Re-usable XPath engine for DOM-like trees

pkgs.perl540Packages.XMLXPathEngine

Re-usable XPath engine for DOM-like trees

pkgs.perl538Packages.ZonemasterEngine

Tool to check the quality of a DNS zone

pkgs.perl540Packages.ZonemasterEngine

Tool to check the quality of a DNS zone

pkgs.perl540Packages.XMLXPathEngine.x86_64-linux

Re-usable XPath engine for DOM-like trees

pkgs.perl540Packages.XMLXPathEngine.aarch64-linux

Re-usable XPath engine for DOM-like trees

pkgs.perl540Packages.XMLXPathEngine.x86_64-darwin

Re-usable XPath engine for DOM-like trees

pkgs.perl540Packages.XMLXPathEngine.aarch64-darwin

Re-usable XPath engine for DOM-like trees

pkgs.perl540Packages.ZonemasterEngine.x86_64-linux

Tool to check the quality of a DNS zone

pkgs.perl540Packages.ZonemasterEngine.aarch64-linux

Tool to check the quality of a DNS zone

pkgs.perl540Packages.ZonemasterEngine.x86_64-darwin

Tool to check the quality of a DNS zone

pkgs.perl540Packages.ZonemasterEngine.aarch64-darwin

Tool to check the quality of a DNS zone
CVE-2023-48733
6.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months, 2 weeks ago
An insecure default to allow UEFI Shell in EDK2 was …

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

edk2
<2023.05-2ubuntu0.1

pkgs.edk2-uefi-shell

UEFI Shell from Tianocore EFI development kit
Package maintainers: 3
CVE-2023-51702
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 6 months, 2 weeks ago
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster. This behavior was changed in version 7.0.0, which stopped serializing the file contents and started providing the file path instead to read the contents into the trigger. Users are recommended to upgrade to version 7.0.0, which fixes this issue.

apache-airflow
<2.6.1
apache-airflow-providers-cncf-kubernetes
<7.0.0

pkgs.apache-airflow

Programmatically author, schedule and monitor data pipelines
Package maintainers: 3
CVE-2024-27318
7.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 6 months, 2 weeks ago
Versions of the package onnx before and including 1.15.0 are …

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.

onnx
=<1.15.0

pkgs.onnxruntime

Cross-platform, high performance scoring engine for ML models

pkgs.python311Packages.onnx

Open Neural Network Exchange

pkgs.python312Packages.onnx

Open Neural Network Exchange

pkgs.python311Packages.onnxmltools

ONNXMLTools enables conversion of models to ONNX

pkgs.python311Packages.onnxruntime

Cross-platform, high performance scoring engine for ML models

pkgs.python312Packages.onnxmltools

ONNXMLTools enables conversion of models to ONNX

pkgs.python312Packages.onnxruntime

Cross-platform, high performance scoring engine for ML models

pkgs.python311Packages.onnxruntime-tools

Transformers Model Optimization Tool of ONNXRuntime

pkgs.python312Packages.onnx.x86_64-linux

Open Neural Network Exchange

pkgs.python312Packages.onnxruntime-tools

Transformers Model Optimization Tool of ONNXRuntime

pkgs.python312Packages.onnx.aarch64-linux

Open Neural Network Exchange

pkgs.python312Packages.onnx.x86_64-darwin

Open Neural Network Exchange

pkgs.python312Packages.onnx.aarch64-darwin

Open Neural Network Exchange

pkgs.python311Packages.onnxconverter-common

ONNX Converter and Optimization Tools

pkgs.python311Packages.rapidocr-onnxruntime

Cross platform OCR Library based on OnnxRuntime

pkgs.python312Packages.onnxconverter-common

ONNX Converter and Optimization Tools

pkgs.python312Packages.rapidocr-onnxruntime

Cross platform OCR Library based on OnnxRuntime

pkgs.python312Packages.skl2onnx.x86_64-linux

Convert scikit-learn models to ONNX

pkgs.python312Packages.skl2onnx.aarch64-linux

Convert scikit-learn models to ONNX

pkgs.python312Packages.skl2onnx.x86_64-darwin

Convert scikit-learn models to ONNX

pkgs.python312Packages.skl2onnx.aarch64-darwin

Convert scikit-learn models to ONNX

pkgs.python312Packages.onnxmltools.x86_64-linux

ONNXMLTools enables conversion of models to ONNX

pkgs.python312Packages.onnxruntime.x86_64-linux

Cross-platform, high performance scoring engine for ML models

pkgs.python312Packages.onnxmltools.aarch64-linux

ONNXMLTools enables conversion of models to ONNX

pkgs.python312Packages.onnxmltools.x86_64-darwin

ONNXMLTools enables conversion of models to ONNX

pkgs.python312Packages.onnxruntime.aarch64-linux

Cross-platform, high performance scoring engine for ML models

pkgs.python312Packages.onnxruntime.x86_64-darwin

Cross-platform, high performance scoring engine for ML models

pkgs.python312Packages.onnxmltools.aarch64-darwin

ONNXMLTools enables conversion of models to ONNX

pkgs.python312Packages.onnxruntime.aarch64-darwin

Cross-platform, high performance scoring engine for ML models

pkgs.python312Packages.onnxruntime-tools.x86_64-linux

Transformers Model Optimization Tool of ONNXRuntime

pkgs.python312Packages.onnxruntime-tools.aarch64-linux

Transformers Model Optimization Tool of ONNXRuntime

pkgs.python312Packages.onnxruntime-tools.x86_64-darwin

Transformers Model Optimization Tool of ONNXRuntime

pkgs.python312Packages.onnxruntime-tools.aarch64-darwin

Transformers Model Optimization Tool of ONNXRuntime

pkgs.python312Packages.onnxconverter-common.x86_64-linux

ONNX Converter and Optimization Tools

pkgs.python312Packages.rapidocr-onnxruntime.x86_64-linux

Cross platform OCR Library based on OnnxRuntime

pkgs.python312Packages.onnxconverter-common.aarch64-linux

ONNX Converter and Optimization Tools

pkgs.python312Packages.onnxconverter-common.x86_64-darwin

ONNX Converter and Optimization Tools

pkgs.python312Packages.rapidocr-onnxruntime.x86_64-darwin

Cross platform OCR Library based on OnnxRuntime

pkgs.python312Packages.onnxconverter-common.aarch64-darwin

ONNX Converter and Optimization Tools

pkgs.python312Packages.rapidocr-onnxruntime.aarch64-darwin

Cross platform OCR Library based on OnnxRuntime
Package maintainers: 6
CVE-2023-1183
5.0 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months, 2 weeks ago
Arbitrary file write

A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.

libreoffice

pkgs.libreoffice-bin

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.hyphenDicts.de_AT

Hyphen dictionary for German (Austria) from LibreOffice

pkgs.hyphenDicts.de_CH

Hyphen dictionary for German (Switzerland) from LibreOffice

pkgs.hyphenDicts.de_DE

Hyphen dictionary for German (Germany) from LibreOffice

pkgs.hunspellDicts.cs_CZ

Hunspell dictionary for Czech (Czechia) from LibreOffice

pkgs.hunspellDicts.el_GR

Hunspell dictionary for Greek (Greece) from LibreOffice

pkgs.hunspellDicts.he_IL

Hunspell dictionary for Hebrew (Israel) from LibreOffice

pkgs.hunspellDicts.hr_HR

Hunspell dictionary for Croatian (Croatia) from LibreOffice

pkgs.hunspellDicts.hu_HU

Hunspell dictionary for Hungarian (Hungary) from LibreOffice

pkgs.hunspellDicts.id_id

Hunspell dictionary for Bahasa Indonesia (Indonesia) from LibreOffice

pkgs.hunspellDicts.nb_NO

Hunspell dictionary for Norwegian Bokmål (Norway) from LibreOffice

pkgs.hunspellDicts.nn_NO

Hunspell dictionary for Norwegian Nynorsk (Norway) from LibreOffice

pkgs.hunspellDicts.pl_PL

Hunspell dictionary for Polish (Poland) from LibreOffice

pkgs.hunspellDicts.pt_BR

Hunspell dictionary for Portuguese (Brazil) from LibreOffice

pkgs.hunspellDicts.pt_PT

Hunspell dictionary for Portuguese (Portugal) from LibreOffice

pkgs.hunspellDicts.ru_RU

Hunspell dictionary for Russian (Russian) from LibreOffice

pkgs.hunspellDicts.sk_SK

Hunspell dictionary for Slovak (Slovakia) from LibreOffice

pkgs.libreoffice-collabora

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-unwrapped

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-unwrapped

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-fresh-unwrapped

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-bin.x86_64-darwin

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-bin.aarch64-darwin

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-fresh.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt-fresh-unwrapped

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-still.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-fresh.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-fresh-unwrapped

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-still-unwrapped

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-still.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt-fresh.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt-still.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-collabora.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt-fresh.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt-still.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-fresh.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-still.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-unwrapped.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-collabora.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-fresh.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-still.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-unwrapped.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-unwrapped.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-unwrapped.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-fresh-unwrapped.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-fresh-unwrapped.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt-fresh-unwrapped.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt-fresh-unwrapped.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-fresh-unwrapped.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-still-unwrapped.x86_64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-fresh-unwrapped.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org

pkgs.libreoffice-qt6-still-unwrapped.aarch64-linux

Comprehensive, professional-quality productivity suite, a variant of openoffice.org
Package maintainers: 4