CVE-2024-45034 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months ago Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised to upgrade to version 2.10.1 or later, which has fixed the vulnerability. Affected products apache-airflow <2.10.1 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3
CVE-2024-45498 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months ago Apache Airflow: Command Injection in an example DAG Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of your DAGs - please review if you have not copied the dangerous example; see https://github.com/apache/airflow/pull/41873 for more information. We recommend against exposing the example DAGs in your deployment. If you must expose the example DAGs, upgrade Airflow to version 2.10.1 or later. Affected products apache-airflow ==2.10.0 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3
CVE-2024-8445 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago 389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for cve-2024-2199) The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input. Affected products 389-ds-base ==3.1.1 * 389-ds:1.4/389-ds-base redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base Matching in nixpkgs pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3 Package maintainers: 1 @ners ners <ners@gmx.ch>
pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3
CVE-2024-8418 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Containers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of service A flaw was found in Aardvark-dns versions 1.12.0 and 1.12.1. They contain a denial of service vulnerability due to serial processing of TCP DNS queries. This flaw allows a malicious client to keep a TCP connection open indefinitely, causing other DNS queries to time out and resulting in a denial of service for all other containers using aardvark-dns. Affected products rhcos aardvark-dns * containers-common containers/aardvark-dns ==1.12.1 ==1.12.0 container-tools:rhel8/aardvark-dns container-tools:rhel8/containers-common Matching in nixpkgs pkgs.aardvark-dns Authoritative dns server for A/AAAA container records nixos-unstable ??? nixpkgs-unstable 1.16.0 Package maintainers: 2 @vdemeester Vincent Demeester <vincent@sbr.pm> @saschagrunert Sascha Grunert <mail@saschagrunert.de>
pkgs.aardvark-dns Authoritative dns server for A/AAAA container records nixos-unstable ??? nixpkgs-unstable 1.16.0
CVE-2024-45620 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Libopensc: incorrect handling of the length of buffers or files in pkcs15init A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. Affected products opensc libopensc Matching in nixpkgs pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45617 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. Affected products opensc libopensc <0.26.0 Matching in nixpkgs pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @pca006132 pca006132 <john.lck40@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45619 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Libopensc: incorrect handling length of buffers or files in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. Affected products opensc libopensc Matching in nixpkgs pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @pca006132 pca006132 <john.lck40@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45618 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15init A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. Affected products opensc libopensc Matching in nixpkgs pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45616 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Libopensc: uninitialized values after incorrect check or usage of apdu response values in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. Affected products opensc libopensc <0.26.0 Matching in nixpkgs pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45615 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Libopensc: pkcs15init: usage of uninitialized values in libopensc and pkcs15init A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. Affected products opensc libopensc <0.26.0 Matching in nixpkgs pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @pca006132 pca006132 <john.lck40@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2