Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2024-1657 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 1 month, 1 week ago Ansible automation platform: insecure websocket used when interacting with eda server A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system. ansible <2.4 ansible-rulebook * automation-eda-controller * ansible-automation-platform-installer * pkgs.ansible-cmdb Generate host overview from ansible fact gathering output nixos-unstable ??? nixpkgs-unstable 1.31 pkgs.ansible-lint Best practices checker for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.2 pkgs.ansible_2_16 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.16.14 pkgs.ansible_2_17 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.17.8 pkgs.ansible_2_18 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.18.8 pkgs.ansible_2_19 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.ansible-doctor Annotation based documentation for your Ansible roles nixos-unstable ??? nixpkgs-unstable 7.2.0 pkgs.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.ansible-navigator Text-based user interface (TUI) for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.ansible-language-server Ansible Language Server nixos-unstable ??? nixpkgs-unstable 1.2.1 pkgs.python312Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0 pkgs.python313Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0 pkgs.terraform-providers.ansible nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.python312Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.python313Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.python312Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python312Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python312Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1 pkgs.python312Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.python313Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python313Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python313Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1 pkgs.python313Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.vscode-extensions.redhat.ansible Ansible language support nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python312Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.python313Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0 pkgs.python312Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2 pkgs.python313Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2 Package maintainers: 13 @StillerHarpo Florian Engel <engelflorian@posteo.de> @HarisDotParis Haris <nix.dev@haris.paris> @robsliwi Robert Sliwinski <r@sliwi.org> @Melkor333 Samuel Ruprecht <samuel@ton-kunst.ch> @dawidd6 Dawid Dziurla <dawidd0811@gmail.com> @geluk Johan Geluk <johan+nix@geluk.io> @GaetanLepage Gaetan Lepage <gaetan@glepage.com> @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru> @tjni Theodore Ni <43ngvg@masqt.com> @tie Ivan Trubach <mr.trubach@icloud.com> @tboerger Thomas Boerger <thomas@webhippie.de> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @sengaya Thilo Uttendorfer <tlo@sengaya.de> CVE-2024-44056 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Mantra theme <= 3.3.2 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Mantra allows Stored XSS.This issue affects Mantra: from n/a through 3.3.2. mantra =<3.3.2 pkgs.mantra Tool used to hunt down API key leaks in JS files and pages nixos-unstable ??? nixpkgs-unstable 3.1 Package maintainers: 1 @fabaff Fabian Affolter <mail@fabian-affolter.ch> CVE-2024-8775 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 1 week ago Ansible: exposure of sensitive information in ansible vault files due to improper logging A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions. ansible ansible-core =<2.17.4 * ee-29-container * ee-minimal-container * ansible-builder-container * discovery-server-container rhelai1/bootc-nvidia-rhel9 discovery/discovery-ui-rhel9 * discovery/discovery-server-rhel9 * ansible-automation-platform/ee-29-rhel8 * ansible-automation-platform/ee-minimal-rhel8 * ansible-automation-platform/ee-minimal-rhel9 * ansible-automation-platform/ansible-builder-rhel8 * ansible-automation-platform/ansible-builder-rhel9 * pkgs.ansible-cmdb Generate host overview from ansible fact gathering output nixos-unstable ??? nixpkgs-unstable 1.31 pkgs.ansible-lint Best practices checker for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.2 pkgs.ansible_2_16 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.16.14 pkgs.ansible_2_17 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.17.8 pkgs.ansible_2_18 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.18.8 pkgs.ansible_2_19 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.ansible-doctor Annotation based documentation for your Ansible roles nixos-unstable ??? nixpkgs-unstable 7.2.0 pkgs.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.ansible-navigator Text-based user interface (TUI) for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.ansible-language-server Ansible Language Server nixos-unstable ??? nixpkgs-unstable 1.2.1 pkgs.python312Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0 pkgs.python313Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0 pkgs.terraform-providers.ansible nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.python312Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.python313Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.python312Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python312Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python312Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1 pkgs.python312Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.python313Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python313Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python313Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1 pkgs.python313Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.vscode-extensions.redhat.ansible Ansible language support nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python312Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.python313Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0 pkgs.python312Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2 pkgs.python313Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2 Package maintainers: 13 @StillerHarpo Florian Engel <engelflorian@posteo.de> @HarisDotParis Haris <nix.dev@haris.paris> @robsliwi Robert Sliwinski <r@sliwi.org> @Melkor333 Samuel Ruprecht <samuel@ton-kunst.ch> @dawidd6 Dawid Dziurla <dawidd0811@gmail.com> @geluk Johan Geluk <johan+nix@geluk.io> @GaetanLepage Gaetan Lepage <gaetan@glepage.com> @tjni Theodore Ni <43ngvg@masqt.com> @tie Ivan Trubach <mr.trubach@icloud.com> @tboerger Thomas Boerger <thomas@webhippie.de> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @sengaya Thilo Uttendorfer <tlo@sengaya.de> @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru> CVE-2024-0874 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago Coredns: cd bit response is cached and served later A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching. coredns <1.11.2 openshift4/ose-coredns * openshift4/ose-coredns-rhel9 * rhacm2/lighthouse-agent-rhel8 rhacm2/lighthouse-agent-rhel9 openshift-logging/logging-loki-rhel8 openshift-logging/logging-loki-rhel9 rhacm2-tech-preview/lighthouse-agent-rhel8 pkgs.coredns DNS server that runs middleware nixos-unstable ??? nixpkgs-unstable 1.12.2 Package maintainers: 4 @rtreffer Rene Treffer <treffer+nixos@measite.de> @djds djds <git@djds.dev> @rushmorem Rushmore Mushambi <rushmore@webenchanter.com> @DeltaEvo Duarte David <deltaduartedavid@gmail.com> CVE-2024-8443 3.4 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago Libopensc: heap buffer overflow in openpgp driver when generating key A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution. opensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @Curious-r Curious <curious@curious.host> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2023-6841 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago Keycloak: amount of attributes per object is not limited and it may lead to dos A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values. keycloak <24.0.0 rh-sso7-keycloak pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4 pkgs.terraform-providers.keycloak nixos-unstable ??? nixpkgs-unstable 5.4.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 Package maintainers: 4 @talyz Kim Lindberger <kim.lindberger@gmail.com> @ngerstle Nicholas Gerstle <ngerstle@gmail.com> @leona-ya Leona Maroni <nix@leona.is> @NickCao Nick Cao <nickcao@nichi.co> CVE-2024-45034 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised to upgrade to version 2.10.1 or later, which has fixed the vulnerability. apache-airflow <2.10.1 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> CVE-2024-45498 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Apache Airflow: Command Injection in an example DAG Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of your DAGs - please review if you have not copied the dangerous example; see https://github.com/apache/airflow/pull/41873 for more information. We recommend against exposing the example DAGs in your deployment. If you must expose the example DAGs, upgrade Airflow to version 2.10.1 or later. apache-airflow ==2.10.0 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> CVE-2024-8445 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago 389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for cve-2024-2199) The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input. 389-ds-base ==3.1.1 * 389-ds:1.4/389-ds-base redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3 Package maintainers: 1 @ners ners <ners@gmx.ch> CVE-2024-8418 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago Containers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of service A flaw was found in Aardvark-dns versions 1.12.0 and 1.12.1. They contain a denial of service vulnerability due to serial processing of TCP DNS queries. This flaw allows a malicious client to keep a TCP connection open indefinitely, causing other DNS queries to time out and resulting in a denial of service for all other containers using aardvark-dns. rhcos aardvark-dns * containers-common containers/aardvark-dns ==1.12.1 ==1.12.0 container-tools:rhel8/aardvark-dns container-tools:rhel8/containers-common pkgs.aardvark-dns Authoritative dns server for A/AAAA container records nixos-unstable ??? nixpkgs-unstable 1.16.0 Package maintainers: 2 @vdemeester Vincent Demeester <vincent@sbr.pm> @saschagrunert Sascha Grunert <mail@saschagrunert.de>
CVE-2024-1657 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 1 month, 1 week ago Ansible automation platform: insecure websocket used when interacting with eda server A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system. ansible <2.4 ansible-rulebook * automation-eda-controller * ansible-automation-platform-installer * pkgs.ansible-cmdb Generate host overview from ansible fact gathering output nixos-unstable ??? nixpkgs-unstable 1.31 pkgs.ansible-lint Best practices checker for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.2 pkgs.ansible_2_16 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.16.14 pkgs.ansible_2_17 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.17.8 pkgs.ansible_2_18 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.18.8 pkgs.ansible_2_19 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.ansible-doctor Annotation based documentation for your Ansible roles nixos-unstable ??? nixpkgs-unstable 7.2.0 pkgs.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.ansible-navigator Text-based user interface (TUI) for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.ansible-language-server Ansible Language Server nixos-unstable ??? nixpkgs-unstable 1.2.1 pkgs.python312Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0 pkgs.python313Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0 pkgs.terraform-providers.ansible nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.python312Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.python313Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.python312Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python312Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python312Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1 pkgs.python312Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.python313Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python313Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python313Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1 pkgs.python313Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.vscode-extensions.redhat.ansible Ansible language support nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python312Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.python313Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0 pkgs.python312Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2 pkgs.python313Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2 Package maintainers: 13 @StillerHarpo Florian Engel <engelflorian@posteo.de> @HarisDotParis Haris <nix.dev@haris.paris> @robsliwi Robert Sliwinski <r@sliwi.org> @Melkor333 Samuel Ruprecht <samuel@ton-kunst.ch> @dawidd6 Dawid Dziurla <dawidd0811@gmail.com> @geluk Johan Geluk <johan+nix@geluk.io> @GaetanLepage Gaetan Lepage <gaetan@glepage.com> @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru> @tjni Theodore Ni <43ngvg@masqt.com> @tie Ivan Trubach <mr.trubach@icloud.com> @tboerger Thomas Boerger <thomas@webhippie.de> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @sengaya Thilo Uttendorfer <tlo@sengaya.de>
pkgs.ansible-cmdb Generate host overview from ansible fact gathering output nixos-unstable ??? nixpkgs-unstable 1.31
pkgs.ansible-doctor Annotation based documentation for your Ansible roles nixos-unstable ??? nixpkgs-unstable 7.2.0
pkgs.ansible-navigator Text-based user interface (TUI) for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.0
pkgs.python312Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0
pkgs.python313Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0
pkgs.python312Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2
pkgs.python313Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2
pkgs.python312Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1
pkgs.python312Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0
pkgs.python312Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1
pkgs.python312Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0
pkgs.python313Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1
pkgs.python313Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0
pkgs.python313Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1
pkgs.python313Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0
pkgs.vscode-extensions.redhat.ansible Ansible language support nixos-unstable ??? nixpkgs-unstable 25.8.1
pkgs.python312Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0
pkgs.python313Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0
pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2
pkgs.python312Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0
pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2
pkgs.python313Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0
pkgs.python312Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2
pkgs.python313Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2
CVE-2024-44056 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Mantra theme <= 3.3.2 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Mantra allows Stored XSS.This issue affects Mantra: from n/a through 3.3.2. mantra =<3.3.2 pkgs.mantra Tool used to hunt down API key leaks in JS files and pages nixos-unstable ??? nixpkgs-unstable 3.1 Package maintainers: 1 @fabaff Fabian Affolter <mail@fabian-affolter.ch>
pkgs.mantra Tool used to hunt down API key leaks in JS files and pages nixos-unstable ??? nixpkgs-unstable 3.1
CVE-2024-8775 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 1 week ago Ansible: exposure of sensitive information in ansible vault files due to improper logging A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions. ansible ansible-core =<2.17.4 * ee-29-container * ee-minimal-container * ansible-builder-container * discovery-server-container rhelai1/bootc-nvidia-rhel9 discovery/discovery-ui-rhel9 * discovery/discovery-server-rhel9 * ansible-automation-platform/ee-29-rhel8 * ansible-automation-platform/ee-minimal-rhel8 * ansible-automation-platform/ee-minimal-rhel9 * ansible-automation-platform/ansible-builder-rhel8 * ansible-automation-platform/ansible-builder-rhel9 * pkgs.ansible-cmdb Generate host overview from ansible fact gathering output nixos-unstable ??? nixpkgs-unstable 1.31 pkgs.ansible-lint Best practices checker for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.2 pkgs.ansible_2_16 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.16.14 pkgs.ansible_2_17 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.17.8 pkgs.ansible_2_18 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.18.8 pkgs.ansible_2_19 Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.ansible-doctor Annotation based documentation for your Ansible roles nixos-unstable ??? nixpkgs-unstable 7.2.0 pkgs.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.ansible-navigator Text-based user interface (TUI) for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.ansible-language-server Ansible Language Server nixos-unstable ??? nixpkgs-unstable 1.2.1 pkgs.python312Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0 pkgs.python313Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0 pkgs.terraform-providers.ansible nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.python312Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.python313Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2 pkgs.python312Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python312Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python312Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1 pkgs.python312Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.python313Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python313Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python313Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1 pkgs.python313Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0 pkgs.vscode-extensions.redhat.ansible Ansible language support nixos-unstable ??? nixpkgs-unstable 25.8.1 pkgs.python312Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.python313Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0 pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.python313Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0 pkgs.python312Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2 pkgs.python313Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2 Package maintainers: 13 @StillerHarpo Florian Engel <engelflorian@posteo.de> @HarisDotParis Haris <nix.dev@haris.paris> @robsliwi Robert Sliwinski <r@sliwi.org> @Melkor333 Samuel Ruprecht <samuel@ton-kunst.ch> @dawidd6 Dawid Dziurla <dawidd0811@gmail.com> @geluk Johan Geluk <johan+nix@geluk.io> @GaetanLepage Gaetan Lepage <gaetan@glepage.com> @tjni Theodore Ni <43ngvg@masqt.com> @tie Ivan Trubach <mr.trubach@icloud.com> @tboerger Thomas Boerger <thomas@webhippie.de> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @sengaya Thilo Uttendorfer <tlo@sengaya.de> @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru>
pkgs.ansible-cmdb Generate host overview from ansible fact gathering output nixos-unstable ??? nixpkgs-unstable 1.31
pkgs.ansible-doctor Annotation based documentation for your Ansible roles nixos-unstable ??? nixpkgs-unstable 7.2.0
pkgs.ansible-navigator Text-based user interface (TUI) for Ansible nixos-unstable ??? nixpkgs-unstable 25.8.0
pkgs.python312Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0
pkgs.python313Packages.ansible Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 11.9.0
pkgs.python312Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2
pkgs.python313Packages.ansible-core Radically simple IT automation nixos-unstable ??? nixpkgs-unstable 2.19.2
pkgs.python312Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1
pkgs.python312Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0
pkgs.python312Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1
pkgs.python312Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0
pkgs.python313Packages.ansible-compat Function collection that help interacting with various versions of Ansible nixos-unstable ??? nixpkgs-unstable 25.8.1
pkgs.python313Packages.ansible-kernel Ansible kernel for Jupyter nixos-unstable ??? nixpkgs-unstable 1.0.0
pkgs.python313Packages.ansible-runner Helps when interfacing with Ansible nixos-unstable ??? nixpkgs-unstable 2.4.1
pkgs.python313Packages.pytest-ansible Plugin for pytest to simplify calling ansible modules from tests or fixtures nixos-unstable ??? nixpkgs-unstable 25.8.0
pkgs.vscode-extensions.redhat.ansible Ansible language support nixos-unstable ??? nixpkgs-unstable 25.8.1
pkgs.python312Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0
pkgs.python313Packages.ansible-builder Ansible execution environment builder nixos-unstable ??? nixpkgs-unstable 3.1.0
pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2
pkgs.python312Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0
pkgs.python313Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable ??? nixpkgs-unstable 1.2.2
pkgs.python313Packages.ansible-vault-rw This project aim to R/W an ansible-vault yaml file nixos-unstable ??? nixpkgs-unstable 2.1.0
pkgs.python312Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2
pkgs.python313Packages.jinja2-ansible-filters Jinja2 Ansible Filters nixos-unstable ??? nixpkgs-unstable jinja2-ansible-filters-1.3.2
CVE-2024-0874 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago Coredns: cd bit response is cached and served later A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching. coredns <1.11.2 openshift4/ose-coredns * openshift4/ose-coredns-rhel9 * rhacm2/lighthouse-agent-rhel8 rhacm2/lighthouse-agent-rhel9 openshift-logging/logging-loki-rhel8 openshift-logging/logging-loki-rhel9 rhacm2-tech-preview/lighthouse-agent-rhel8 pkgs.coredns DNS server that runs middleware nixos-unstable ??? nixpkgs-unstable 1.12.2 Package maintainers: 4 @rtreffer Rene Treffer <treffer+nixos@measite.de> @djds djds <git@djds.dev> @rushmorem Rushmore Mushambi <rushmore@webenchanter.com> @DeltaEvo Duarte David <deltaduartedavid@gmail.com>
CVE-2024-8443 3.4 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago Libopensc: heap buffer overflow in openpgp driver when generating key A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution. opensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @Curious-r Curious <curious@curious.host> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2023-6841 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago Keycloak: amount of attributes per object is not limited and it may lead to dos A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values. keycloak <24.0.0 rh-sso7-keycloak pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4 pkgs.terraform-providers.keycloak nixos-unstable ??? nixpkgs-unstable 5.4.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 Package maintainers: 4 @talyz Kim Lindberger <kim.lindberger@gmail.com> @ngerstle Nicholas Gerstle <ngerstle@gmail.com> @leona-ya Leona Maroni <nix@leona.is> @NickCao Nick Cao <nickcao@nichi.co>
pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4
pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0
pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0
CVE-2024-45034 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised to upgrade to version 2.10.1 or later, which has fixed the vulnerability. apache-airflow <2.10.1 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3
CVE-2024-45498 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Apache Airflow: Command Injection in an example DAG Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of your DAGs - please review if you have not copied the dangerous example; see https://github.com/apache/airflow/pull/41873 for more information. We recommend against exposing the example DAGs in your deployment. If you must expose the example DAGs, upgrade Airflow to version 2.10.1 or later. apache-airflow ==2.10.0 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable ??? nixpkgs-unstable 2.7.3
CVE-2024-8445 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago 389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for cve-2024-2199) The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input. 389-ds-base ==3.1.1 * 389-ds:1.4/389-ds-base redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3 Package maintainers: 1 @ners ners <ners@gmx.ch>
pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3
CVE-2024-8418 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago Containers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of service A flaw was found in Aardvark-dns versions 1.12.0 and 1.12.1. They contain a denial of service vulnerability due to serial processing of TCP DNS queries. This flaw allows a malicious client to keep a TCP connection open indefinitely, causing other DNS queries to time out and resulting in a denial of service for all other containers using aardvark-dns. rhcos aardvark-dns * containers-common containers/aardvark-dns ==1.12.1 ==1.12.0 container-tools:rhel8/aardvark-dns container-tools:rhel8/containers-common pkgs.aardvark-dns Authoritative dns server for A/AAAA container records nixos-unstable ??? nixpkgs-unstable 1.16.0 Package maintainers: 2 @vdemeester Vincent Demeester <vincent@sbr.pm> @saschagrunert Sascha Grunert <mail@saschagrunert.de>
pkgs.aardvark-dns Authoritative dns server for A/AAAA container records nixos-unstable ??? nixpkgs-unstable 1.16.0