⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2024-3049
5.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 8 months ago
Booth: specially crafted hash can lead to invalid hmac being accepted by booth server

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.

booth
*
==1.0-283.1

pkgs.libsForQt5.booth

Camera application

pkgs.plasma5Packages.booth

Camera application

pkgs.libsForQt5.booth.x86_64-linux

Camera application

pkgs.libsForQt5.booth.aarch64-linux

Camera application

pkgs.plasma5Packages.booth.x86_64-linux

Camera application

pkgs.plasma5Packages.booth.aarch64-linux

Camera application
Package maintainers: 1
CVE-2024-47515
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 8 months ago
Pagure: generate_archive() follows symbolic links in temporary clones

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.

pagure
==5.14.1

pkgs.haskellPackages.pagure

Pagure REST client library

pkgs.haskellPackages.pagure-cli

Pagure client
CVE-2024-4871
6.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 8 months ago
Foreman: host ssh key not being checked in remote execution

A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.

foreman
*
==3.9.1.8
candlepin
*
satellite
*
python-pulpcore
*
rubygem-dynflow
*
rubygem-katello
*
foreman-installer
*
python-pulp-container
*
rubygem-foreman_ansible
*
rubygem-foreman_remote_execution
*
rubygem-smart_proxy_container_gateway
*
rubygem-smart_proxy_remote_execution_ssh
*

pkgs.foreman

Process manager for applications with multiple components

pkgs.satellite

Program for showing navigation satellite data

pkgs.wyoming-satellite

Remote voice satellite using Wyoming protocol

pkgs.xwayland-satellite

Xwayland outside your Wayland compositor

pkgs.satellite.x86_64-linux

Program for showing navigation satellite data

pkgs.homeassistant-satellite

Streaming audio satellite for Home Assistant

pkgs.satellite.aarch64-linux

Program for showing navigation satellite data

pkgs.home-assistant-component-tests.assist_satellite

Open source home automation that puts local control and privacy first
Package maintainers: 8
CVE-2024-9666
4.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 8 months ago
Org.keycloak/keycloak-quarkus-server: keycloak proxy header handling denial-of-service (dos) vulnerability

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.

keycloak
<26.0.6
<24.0.9
rhbk/keycloak-rhel9
*
rhbk/keycloak-rhel9-operator
*
rhbk/keycloak-operator-bundle
*
org.keycloak/keycloak-quarkus-server

pkgs.keycloak

Identity and access management for modern applications and services

pkgs.terraform-providers.keycloak

pkgs.python311Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API
Package maintainers: 3
CVE-2024-4629
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 8 months ago
Keycloak: potential bypass of brute force protection

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.

keycloak
==24.0.3
rh-sso7-keycloak
*
rhbk/keycloak-rhel9
*
org.keycloak-keycloak-parent
rhbk/keycloak-rhel9-operator
*
rhbk/keycloak-operator-bundle
*
rh-sso-7/sso76-openshift-rhel8
*

pkgs.keycloak

Identity and access management for modern applications and services

pkgs.terraform-providers.keycloak

pkgs.python311Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API
Package maintainers: 3
CVE-2024-2199
5.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): ADJACENT_NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 8 months ago
389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.c

A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.

389-ds:1.4
*
389-ds-base
*
<3.1.1
redhat-ds:11
*
redhat-ds:12
*
389-ds:1.4/389-ds-base
redhat-ds:11/389-ds-base
redhat-ds:12/389-ds-base

pkgs._389-ds-base

Enterprise-class Open Source LDAP server for Linux
Package maintainers: 1
CVE-2024-9427
5.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 8 months ago
Koji: escape html tag characters in the query string

A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code

koji
<1.35.1

pkgs.koji

Interactive CLI for creating conventional commits

pkgs.haskellPackages.koji

Koji buildsystem XML-RPC API bindings

pkgs.haskellPackages.koji.x86_64-linux

Koji buildsystem XML-RPC API bindings

pkgs.haskellPackages.koji.aarch64-linux

Koji buildsystem XML-RPC API bindings

pkgs.haskellPackages.koji.x86_64-darwin

Koji buildsystem XML-RPC API bindings

pkgs.haskellPackages.koji.aarch64-darwin

Koji buildsystem XML-RPC API bindings
Package maintainers: 1
CVE-2024-12840
5.0 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 8 months, 1 week ago
Http proxies: satellite: service side request forgery in http proxies

A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with the http_proxies variable set to localhost, the attacker can fetch the localhost banner.

security

pkgs.libmodsecurity

ModSecurity v3 library component.

pkgs.xml-security-c

C++ Implementation of W3C security standards for XML

pkgs.modsecurity-crs

The OWASP ModSecurity Core Rule Set is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls.

pkgs.modsecurity_standalone

Open source, cross-platform web application firewall (WAF)

pkgs.libmodsecurity.x86_64-linux

ModSecurity v3 library component.

pkgs.libmodsecurity.aarch64-linux

ModSecurity v3 library component.

pkgs.libmodsecurity.x86_64-darwin

ModSecurity v3 library component.

pkgs.libmodsecurity.aarch64-darwin

ModSecurity v3 library component.

pkgs.haskellPackages.hackage-security

Hackage security library

pkgs.python311Packages.flask-security

Quickly add security features to your Flask application

pkgs.python312Packages.flask-security

Quickly add security features to your Flask application

pkgs.python311Packages.securityreporter

Python wrapper for the Reporter API

pkgs.python312Packages.securityreporter

Python wrapper for the Reporter API

pkgs.haskellPackages.amazonka-securityhub

Amazon SecurityHub SDK

pkgs.haskellPackages.amazonka-securitylake

Amazon Security Lake SDK

pkgs.haskellPackages.hackage-security-HTTP

Hackage security bindings against the HTTP library

pkgs.python311Packages.azure-mgmt-security

Microsoft Azure Security Center Management Client Library for Python

pkgs.python312Packages.azure-mgmt-security

Microsoft Azure Security Center Management Client Library for Python

pkgs.pantheon.switchboard-plug-security-privacy

Switchboard Security & Privacy Plug

pkgs.haskellPackages.hackage-security.x86_64-linux

Hackage security library

pkgs.python311Packages.google-cloud-securitycenter

Cloud Security Command Center API API client library

pkgs.python312Packages.flask-security.x86_64-linux

Quickly add security features to your Flask application

pkgs.python312Packages.google-cloud-securitycenter

Cloud Security Command Center API API client library

pkgs.azure-cli-extensions.hardware-security-modules

Microsoft Azure Command-Line Tools AzureDedicatedHSMResourceProvider Extension

pkgs.haskellPackages.hackage-security.aarch64-linux

Hackage security library

pkgs.haskellPackages.hackage-security.x86_64-darwin

Hackage security library

pkgs.python312Packages.flask-security.aarch64-linux

Quickly add security features to your Flask application

pkgs.python312Packages.flask-security.x86_64-darwin

Quickly add security features to your Flask application

pkgs.haskellPackages.hackage-security.aarch64-darwin

Hackage security library

pkgs.python311Packages.types-aiobotocore-securityhub

Type annotations for aiobotocore securityhub

pkgs.python312Packages.flask-security.aarch64-darwin

Quickly add security features to your Flask application

pkgs.python312Packages.securityreporter.x86_64-linux

Python wrapper for the Reporter API

pkgs.python312Packages.types-aiobotocore-securityhub

Type annotations for aiobotocore securityhub

pkgs.python311Packages.types-aiobotocore-securitylake

Type annotations for aiobotocore securitylake

pkgs.python312Packages.securityreporter.aarch64-linux

Python wrapper for the Reporter API

pkgs.python312Packages.securityreporter.x86_64-darwin

Python wrapper for the Reporter API

pkgs.python312Packages.types-aiobotocore-securitylake

Type annotations for aiobotocore securitylake

pkgs.python311Packages.google-cloud-websecurityscanner

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.google-cloud-websecurityscanner

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.securityreporter.aarch64-darwin

Python wrapper for the Reporter API

pkgs.haskellPackages.hackage-security-HTTP.x86_64-linux

Hackage security bindings against the HTTP library

pkgs.haskellPackages.hackage-security-HTTP.aarch64-linux

Hackage security bindings against the HTTP library

pkgs.haskellPackages.hackage-security-HTTP.x86_64-darwin

Hackage security bindings against the HTTP library

pkgs.haskellPackages.hackage-security-HTTP.aarch64-darwin

Hackage security bindings against the HTTP library

pkgs.python311Packages.types-aiobotocore-codeguru-security

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.mypy-boto3-securityhub.x86_64-linux

Type annotations for boto3 securityhub

pkgs.python312Packages.types-aiobotocore-codeguru-security

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.mypy-boto3-securityhub.aarch64-linux

Type annotations for boto3 securityhub

pkgs.python312Packages.mypy-boto3-securityhub.x86_64-darwin

Type annotations for boto3 securityhub

pkgs.python312Packages.mypy-boto3-securitylake.x86_64-linux

Type annotations for boto3 securitylake

pkgs.python312Packages.mypy-boto3-securityhub.aarch64-darwin

Type annotations for boto3 securityhub

pkgs.python312Packages.mypy-boto3-securitylake.aarch64-linux

Type annotations for boto3 securitylake

pkgs.python312Packages.mypy-boto3-securitylake.x86_64-darwin

Type annotations for boto3 securitylake

pkgs.python312Packages.mypy-boto3-securitylake.aarch64-darwin

Type annotations for boto3 securitylake

pkgs.gnomeExtensions.arch-linux-updates-and-security-indicator

Update indicator for Arch Linux and GNOME Shell.
  • nixos-unstable 2
    • nixos-unstable-small 2
    • nixpkgs-unstable 2

pkgs.python312Packages.google-cloud-securitycenter.x86_64-linux

Cloud Security Command Center API API client library

pkgs.python312Packages.google-cloud-securitycenter.aarch64-linux

Cloud Security Command Center API API client library

pkgs.python312Packages.google-cloud-securitycenter.x86_64-darwin

Cloud Security Command Center API API client library

pkgs.python311Packages.microsoft-security-utilities-secret-masker

A tool for detecting and masking secrets

pkgs.python312Packages.google-cloud-securitycenter.aarch64-darwin

Cloud Security Command Center API API client library

pkgs.python312Packages.microsoft-security-utilities-secret-masker

A tool for detecting and masking secrets

pkgs.python312Packages.types-aiobotocore-securityhub.x86_64-linux

Type annotations for aiobotocore securityhub

pkgs.python312Packages.types-aiobotocore-securityhub.aarch64-linux

Type annotations for aiobotocore securityhub

pkgs.python312Packages.types-aiobotocore-securityhub.x86_64-darwin

Type annotations for aiobotocore securityhub

pkgs.python312Packages.types-aiobotocore-securitylake.x86_64-linux

Type annotations for aiobotocore securitylake

pkgs.python312Packages.google-cloud-websecurityscanner.x86_64-linux

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.types-aiobotocore-securityhub.aarch64-darwin

Type annotations for aiobotocore securityhub

pkgs.python312Packages.types-aiobotocore-securitylake.aarch64-linux

Type annotations for aiobotocore securitylake

pkgs.python312Packages.types-aiobotocore-securitylake.x86_64-darwin

Type annotations for aiobotocore securitylake

pkgs.python312Packages.google-cloud-websecurityscanner.aarch64-linux

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.google-cloud-websecurityscanner.x86_64-darwin

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.types-aiobotocore-securitylake.aarch64-darwin

Type annotations for aiobotocore securitylake

pkgs.python312Packages.google-cloud-websecurityscanner.aarch64-darwin

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.types-aiobotocore-codeguru-security.x86_64-linux

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.types-aiobotocore-codeguru-security.aarch64-linux

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.types-aiobotocore-codeguru-security.x86_64-darwin

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.types-aiobotocore-codeguru-security.aarch64-darwin

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.microsoft-security-utilities-secret-masker.x86_64-linux

A tool for detecting and masking secrets

pkgs.python312Packages.microsoft-security-utilities-secret-masker.aarch64-linux

A tool for detecting and masking secrets

pkgs.python312Packages.microsoft-security-utilities-secret-masker.x86_64-darwin

A tool for detecting and masking secrets

pkgs.python312Packages.microsoft-security-utilities-secret-masker.aarch64-darwin

A tool for detecting and masking secrets
Package maintainers: 12
CVE-2024-1132
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 8 months, 1 week ago
Keycloak: path transversal in redirection validation

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

keycloak
<24.0.3
<22.0.10
keycloak-core
rh-sso7-keycloak
*
rhbk/keycloak-rhel9
*
mtr/mtr-rhel8-operator
*
mtr/mtr-operator-bundle
*
mta/mta-windup-addon-rhel9
*
org.keycloak/keycloak-core
mtr/mtr-web-container-rhel8
*
org.keycloak-keycloak-parent
rhbk/keycloak-rhel9-operator
*
rhbk/keycloak-operator-bundle
*
rh-sso-7/sso76-openshift-rhel8
*
mtr/mtr-web-executor-container-rhel8
*
org.wildfly.security-wildfly-elytron-parent

pkgs.keycloak

Identity and access management for modern applications and services

pkgs.terraform-providers.keycloak

pkgs.python311Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API
Package maintainers: 3
CVE-2024-37962
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 8 months, 1 week ago
WordPress Fusion Page Builder plugin <= 1.6.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Fusion allows Stored XSS.This issue affects Fusion: from n/a through 1.6.1.

fusion
=<1.6.1

pkgs.datafusion-cli

cli for Apache Arrow DataFusion

pkgs.lxgw-fusionkai

Simplified Chinese font derived from LXGW WenKai GB, iansui and Klee One

pkgs.finalfusion-utils

Utility for converting, quantizing, and querying word embeddings

pkgs.python311Packages.datafusion

Extensible query execution framework

pkgs.python312Packages.datafusion

Extensible query execution framework

pkgs.haskellPackages.fusion-plugin

GHC plugin to make stream fusion more predictable

pkgs.python311Packages.finalfusion

Python module for using finalfusion, word2vec, and fastText word embeddings

pkgs.python312Packages.finalfusion

Python module for using finalfusion, word2vec, and fastText word embeddings

pkgs.haskellPackages.fusion-plugin-types

Types for the fusion-plugin package

pkgs.vimPlugins.nvim-treesitter-parsers.fusion

  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.haskellPackages.fusion-plugin.x86_64-linux

GHC plugin to make stream fusion more predictable

pkgs.python312Packages.k-diffusion.x86_64-linux

Karras et al. (2022) diffusion models for PyTorch

pkgs.haskellPackages.fusion-plugin.aarch64-linux

GHC plugin to make stream fusion more predictable

pkgs.haskellPackages.fusion-plugin.x86_64-darwin

GHC plugin to make stream fusion more predictable

pkgs.python312Packages.k-diffusion.aarch64-linux

Karras et al. (2022) diffusion models for PyTorch

pkgs.python312Packages.k-diffusion.x86_64-darwin

Karras et al. (2022) diffusion models for PyTorch

pkgs.haskellPackages.fusion-plugin.aarch64-darwin

GHC plugin to make stream fusion more predictable

pkgs.haskellPackages.fusion-plugin-types.x86_64-linux

Types for the fusion-plugin package

pkgs.haskellPackages.fusion-plugin-types.aarch64-linux

Types for the fusion-plugin package

pkgs.haskellPackages.fusion-plugin-types.x86_64-darwin

Types for the fusion-plugin package

pkgs.haskellPackages.fusion-plugin-types.aarch64-darwin

Types for the fusion-plugin package
Package maintainers: 4