Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2024-3250 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month ago It was discovered that Canonical's Pebble service manager read-file API … It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4. pebble <v1.10.2 pkgs.pebble Small RFC 8555 ACME test server nixos-unstable ??? nixpkgs-unstable 2.6.0 pkgs.python312Packages.pebble API to manage threads and processes within an application nixos-unstable ??? nixpkgs-unstable 5.1.3 pkgs.python313Packages.pebble API to manage threads and processes within an application nixos-unstable ??? nixpkgs-unstable 5.1.3 Package maintainers: 6 @orivej Orivej Desh <orivej@gmx.fr> @flokli Florian Klink <flokli@flokli.de> @arianvp Arian van Putten <arian.vanputten@gmail.com> @m1cr0man Lucas Savva <lucas+nix@m1cr0man.com> @aanderse Aaron Andersen <aaron@fosslib.net> @emilazy Emily <nixpkgs@emily.moe> CVE-2024-25096 10.0 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago WordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerability Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. canto =<3.0.7 pkgs.cantoolz Black-box CAN network analysis framework nixos-unstable ??? nixpkgs-unstable 3.7.0 pkgs.canto-curses Ncurses-based console Atom/RSS feed reader nixos-unstable ??? nixpkgs-unstable 0.9.9 pkgs.canto-daemon Daemon for the canto Atom/RSS feed reader nixos-unstable ??? nixpkgs-unstable 0.9.8 pkgs.kdePackages.cantor Front end to powerful mathematics and statistics packages nixos-unstable ??? nixpkgs-unstable 25.08.1 pkgs.python312Packages.cantools Tools to work with CAN bus nixos-unstable ??? nixpkgs-unstable 40.5.0 pkgs.python313Packages.cantools Tools to work with CAN bus nixos-unstable ??? nixpkgs-unstable 40.5.0 pkgs.haskellPackages.cantor-pairing Convert data to and from a natural number representation nixos-unstable ??? nixpkgs-unstable 0.2.0.2 Package maintainers: 10 @mjm Matt Moriarity <matt@mattmoriarity.com> @K900 Ilya K. <me@0upti.me> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @NickCao Nick Cao <nickcao@nichi.co> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @devhell devhell <"^"@regexmail.net> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @gray-heron Cezary Siwek <ave+nix@cezar.info> CVE-2024-31420 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month ago Cnv: dos through repeatedly calling vm-dump-metrics until virt handler crashes A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine. cnv ==4.15.0 kubevirt pkgs.kubevirt Client tool to use advanced features such as console access nixos-unstable ??? nixpkgs-unstable 1.6.0 Package maintainers: 1 @haslersn Sebastian Hasler <haslersn@fius.informatik.uni-stuttgart.de> CVE-2024-31107 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month ago WordPress OpenID plugin <= 3.6.1 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DiSo Development Team OpenID allows Reflected XSS.This issue affects OpenID: from n/a through 3.6.1. openid =<3.6.1 pkgs.luaPackages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.python312Packages.flask-openid OpenID support for Flask nixos-unstable ??? nixpkgs-unstable 1.3.1 pkgs.python313Packages.flask-openid OpenID support for Flask nixos-unstable ??? nixpkgs-unstable 1.3.1 pkgs.lua51Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.lua52Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.lua53Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.lua54Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.luajitPackages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.python312Packages.openidc-client CLI python OpenID Connect client with token caching and management nixos-unstable ??? nixpkgs-unstable 0.6.0 pkgs.python312Packages.python3-openid OpenID support for modern servers and consumers nixos-unstable ??? nixpkgs-unstable python3-openid-3.2.0 pkgs.python313Packages.openidc-client CLI python OpenID Connect client with token caching and management nixos-unstable ??? nixpkgs-unstable 0.6.0 pkgs.python313Packages.python3-openid OpenID support for modern servers and consumers nixos-unstable ??? nixpkgs-unstable python3-openid-3.2.0 Package maintainers: 1 @disassembler Samuel Leathers <disasm@gmail.com> CVE-2024-3094 10.0 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Xz: malicious code in distributed source Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library. xz ==5.6.0 ==5.6.1 pkgs.xz General-purpose data compression software, successor of LZMA nixos-unstable ??? nixpkgs-unstable 5.8.1 pkgs.pxz Compression utility that runs LZMA compression of different parts on multiple cores simultaneously nixos-unstable ??? nixpkgs-unstable 4.999.9beta pkgs.pixz Parallel compressor/decompressor for xz format nixos-unstable ??? nixpkgs-unstable 1.0.7 pkgs.xzgv Picture viewer for X with a thumbnail-based selector nixos-unstable ??? nixpkgs-unstable 0.9.2 pkgs.xzoom X11 screen zoom tool nixos-unstable ??? nixpkgs-unstable 0.3 pkgs.haskellPackages.xz LZMA/XZ compression and decompression nixos-unstable ??? nixpkgs-unstable 5.6.3 pkgs.tests.fetchzip.simple nixos-unstable ??? nixpkgs-unstable xzxd07yccxqd pkgs.plymouth-proxzima-theme Techno Plymouth theme with crazy animation nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-01-30 pkgs.python312Packages.txzmq Twisted bindings for ZeroMQ nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python313Packages.txzmq Twisted bindings for ZeroMQ nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python312Packages.python-xz Pure Python library for seeking within compressed xz files nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.python313Packages.python-xz Pure Python library for seeking within compressed xz files nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.typstPackages.exzellenz-tum-thesis_0_1_0 Customizable template for a thesis at the TU Munich nixos-unstable ??? nixpkgs-unstable 0.1.0 pkgs.tests.pkg-config.defaultPkgConfigPackages.liblzma Test whether xz-5.8.1 exposes pkg-config modules liblzma nixos-unstable ??? nixpkgs-unstable Package maintainers: 7 @7c6f434c Michael Raskin <7c6f434c@mail.ru> @mxmlnkn Maximilian Knespel @johnrtitor Masum Reza <masumrezarock100@gmail.com> @ip1981 Igor Pashev <pashev.igor@gmail.com> @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @womfoo Kranium Gikos Mendoza <kranium@gikos.net> @cherrypiejam Gongqi Huang CVE-2024-2947 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Cockpit: command injection when deleting a sosreport with a crafted name A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer. cockpit * * pkgs.cockpit Web-based graphical interface for servers nixos-unstable ??? nixpkgs-unstable 346 Package maintainers: 1 @lucasew Lucas Eduardo Wendt <lucas59356@gmail.com> CVE-2024-3019 8.8 HIGH CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Pcp: exposure of the redis server backend allows remote command execution via pmproxy A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer. pcp * * pkgs.pcp Command line peer-to-peer data transfer tool based on libp2p nixos-unstable ??? nixpkgs-unstable 0.4.0 pkgs.ncmpcpp Featureful ncurses based MPD client inspired by ncmpc nixos-unstable ??? nixpkgs-unstable 0.10.1 pkgs.libamqpcpp Library for communicating with a RabbitMQ server nixos-unstable ??? nixpkgs-unstable 4.3.27 pkgs.python312Packages.pcpp C99 preprocessor written in pure Python nixos-unstable ??? nixpkgs-unstable 1.30 pkgs.python313Packages.pcpp C99 preprocessor written in pure Python nixos-unstable ??? nixpkgs-unstable 1.30 Package maintainers: 5 @lovek323 Jason O'Conal <jason@oconal.id.au> @k0ral Koral <koral@mailoo.org> @MikePlayle Mike Playle <mike@mythik.co.uk> @Rakesh4G Rakesh Gupta <rakeshgupta4u@gmail.com> @MatthewCroughan Matthew Croughan <matt@croughan.sh> CVE-2024-30229 8.0 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability Deserialization of Untrusted Data vulnerability in GiveWP.This issue affects GiveWP: from n/a through 3.4.2. give =<3.4.2 pkgs.filegive Easy p2p file sending program nixos-unstable ??? nixpkgs-unstable 2022-05-29 CVE-2024-29815 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month ago WordPress WP Change Email Sender plugin < 1.3.0 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Change Email Sender allows Stored XSS.This issue affects WP Change Email Sender: from n/a before 1.3.0. wp-change-email-sender <1.3.0 pkgs.wordpressPackages.plugins.wp-change-email-sender nixos-unstable ??? nixpkgs-unstable 3.0 CVE-2024-29768 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month ago WordPress Astra theme <= 4.6.4 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4. astra =<4.6.4 pkgs.astral Tool for estimating an unrooted species tree given a set of unrooted gene trees nixos-unstable ??? nixpkgs-unstable 5.7.1 pkgs.akkuPackages.riastradh Libraries by Taylor Campbell ported to Chez Scheme nixos-unstable ??? nixpkgs-unstable 0.0.0-akku.16.9714b5c pkgs.python312Packages.astral Calculations for the position of the sun and the moon nixos-unstable ??? nixpkgs-unstable 3.2 pkgs.python313Packages.astral Calculations for the position of the sun and the moon nixos-unstable ??? nixpkgs-unstable 3.2 pkgs.gnomeExtensions.astra-monitor Astra Monitor is a cutting-edge, fully customizable, and performance-focused system monitoring extension for GNOME's top bar. It's an all-in-one solution for those seeking to keep a close eye on their system's performance metrics like CPU, GPU, RAM, disk usage, network statistics, and sensor readings. nixos-unstable ??? nixpkgs-unstable 51 pkgs.gnomeExtensions.astrapios-panel-menu A GNOME Shell Extension to add custom menu to panel nixos-unstable ??? nixpkgs-unstable 6 Package maintainers: 4 @flokli Florian Klink <flokli@flokli.de> @honnip Jung seungwoo <me@honnip.page> @bzizou Bruno Bzeznik <Bruno@bzizou.net> @TomaSajt TomaSajt
CVE-2024-3250 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month ago It was discovered that Canonical's Pebble service manager read-file API … It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4. pebble <v1.10.2 pkgs.pebble Small RFC 8555 ACME test server nixos-unstable ??? nixpkgs-unstable 2.6.0 pkgs.python312Packages.pebble API to manage threads and processes within an application nixos-unstable ??? nixpkgs-unstable 5.1.3 pkgs.python313Packages.pebble API to manage threads and processes within an application nixos-unstable ??? nixpkgs-unstable 5.1.3 Package maintainers: 6 @orivej Orivej Desh <orivej@gmx.fr> @flokli Florian Klink <flokli@flokli.de> @arianvp Arian van Putten <arian.vanputten@gmail.com> @m1cr0man Lucas Savva <lucas+nix@m1cr0man.com> @aanderse Aaron Andersen <aaron@fosslib.net> @emilazy Emily <nixpkgs@emily.moe>
pkgs.python312Packages.pebble API to manage threads and processes within an application nixos-unstable ??? nixpkgs-unstable 5.1.3
pkgs.python313Packages.pebble API to manage threads and processes within an application nixos-unstable ??? nixpkgs-unstable 5.1.3
CVE-2024-25096 10.0 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago WordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerability Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. canto =<3.0.7 pkgs.cantoolz Black-box CAN network analysis framework nixos-unstable ??? nixpkgs-unstable 3.7.0 pkgs.canto-curses Ncurses-based console Atom/RSS feed reader nixos-unstable ??? nixpkgs-unstable 0.9.9 pkgs.canto-daemon Daemon for the canto Atom/RSS feed reader nixos-unstable ??? nixpkgs-unstable 0.9.8 pkgs.kdePackages.cantor Front end to powerful mathematics and statistics packages nixos-unstable ??? nixpkgs-unstable 25.08.1 pkgs.python312Packages.cantools Tools to work with CAN bus nixos-unstable ??? nixpkgs-unstable 40.5.0 pkgs.python313Packages.cantools Tools to work with CAN bus nixos-unstable ??? nixpkgs-unstable 40.5.0 pkgs.haskellPackages.cantor-pairing Convert data to and from a natural number representation nixos-unstable ??? nixpkgs-unstable 0.2.0.2 Package maintainers: 10 @mjm Matt Moriarity <matt@mattmoriarity.com> @K900 Ilya K. <me@0upti.me> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @NickCao Nick Cao <nickcao@nichi.co> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @devhell devhell <"^"@regexmail.net> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @gray-heron Cezary Siwek <ave+nix@cezar.info>
pkgs.canto-curses Ncurses-based console Atom/RSS feed reader nixos-unstable ??? nixpkgs-unstable 0.9.9
pkgs.canto-daemon Daemon for the canto Atom/RSS feed reader nixos-unstable ??? nixpkgs-unstable 0.9.8
pkgs.kdePackages.cantor Front end to powerful mathematics and statistics packages nixos-unstable ??? nixpkgs-unstable 25.08.1
pkgs.python312Packages.cantools Tools to work with CAN bus nixos-unstable ??? nixpkgs-unstable 40.5.0
pkgs.python313Packages.cantools Tools to work with CAN bus nixos-unstable ??? nixpkgs-unstable 40.5.0
pkgs.haskellPackages.cantor-pairing Convert data to and from a natural number representation nixos-unstable ??? nixpkgs-unstable 0.2.0.2
CVE-2024-31420 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month ago Cnv: dos through repeatedly calling vm-dump-metrics until virt handler crashes A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine. cnv ==4.15.0 kubevirt pkgs.kubevirt Client tool to use advanced features such as console access nixos-unstable ??? nixpkgs-unstable 1.6.0 Package maintainers: 1 @haslersn Sebastian Hasler <haslersn@fius.informatik.uni-stuttgart.de>
pkgs.kubevirt Client tool to use advanced features such as console access nixos-unstable ??? nixpkgs-unstable 1.6.0
CVE-2024-31107 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month ago WordPress OpenID plugin <= 3.6.1 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DiSo Development Team OpenID allows Reflected XSS.This issue affects OpenID: from n/a through 3.6.1. openid =<3.6.1 pkgs.luaPackages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.python312Packages.flask-openid OpenID support for Flask nixos-unstable ??? nixpkgs-unstable 1.3.1 pkgs.python313Packages.flask-openid OpenID support for Flask nixos-unstable ??? nixpkgs-unstable 1.3.1 pkgs.lua51Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.lua52Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.lua53Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.lua54Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.luajitPackages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1 pkgs.python312Packages.openidc-client CLI python OpenID Connect client with token caching and management nixos-unstable ??? nixpkgs-unstable 0.6.0 pkgs.python312Packages.python3-openid OpenID support for modern servers and consumers nixos-unstable ??? nixpkgs-unstable python3-openid-3.2.0 pkgs.python313Packages.openidc-client CLI python OpenID Connect client with token caching and management nixos-unstable ??? nixpkgs-unstable 0.6.0 pkgs.python313Packages.python3-openid OpenID support for modern servers and consumers nixos-unstable ??? nixpkgs-unstable python3-openid-3.2.0 Package maintainers: 1 @disassembler Samuel Leathers <disasm@gmail.com>
pkgs.luaPackages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1
pkgs.python312Packages.flask-openid OpenID support for Flask nixos-unstable ??? nixpkgs-unstable 1.3.1
pkgs.python313Packages.flask-openid OpenID support for Flask nixos-unstable ??? nixpkgs-unstable 1.3.1
pkgs.lua51Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1
pkgs.lua52Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1
pkgs.lua53Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1
pkgs.lua54Packages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1
pkgs.luajitPackages.lua-resty-openidc A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality nixos-unstable ??? nixpkgs-unstable 1.8.0-1
pkgs.python312Packages.openidc-client CLI python OpenID Connect client with token caching and management nixos-unstable ??? nixpkgs-unstable 0.6.0
pkgs.python312Packages.python3-openid OpenID support for modern servers and consumers nixos-unstable ??? nixpkgs-unstable python3-openid-3.2.0
pkgs.python313Packages.openidc-client CLI python OpenID Connect client with token caching and management nixos-unstable ??? nixpkgs-unstable 0.6.0
pkgs.python313Packages.python3-openid OpenID support for modern servers and consumers nixos-unstable ??? nixpkgs-unstable python3-openid-3.2.0
CVE-2024-3094 10.0 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Xz: malicious code in distributed source Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library. xz ==5.6.0 ==5.6.1 pkgs.xz General-purpose data compression software, successor of LZMA nixos-unstable ??? nixpkgs-unstable 5.8.1 pkgs.pxz Compression utility that runs LZMA compression of different parts on multiple cores simultaneously nixos-unstable ??? nixpkgs-unstable 4.999.9beta pkgs.pixz Parallel compressor/decompressor for xz format nixos-unstable ??? nixpkgs-unstable 1.0.7 pkgs.xzgv Picture viewer for X with a thumbnail-based selector nixos-unstable ??? nixpkgs-unstable 0.9.2 pkgs.xzoom X11 screen zoom tool nixos-unstable ??? nixpkgs-unstable 0.3 pkgs.haskellPackages.xz LZMA/XZ compression and decompression nixos-unstable ??? nixpkgs-unstable 5.6.3 pkgs.tests.fetchzip.simple nixos-unstable ??? nixpkgs-unstable xzxd07yccxqd pkgs.plymouth-proxzima-theme Techno Plymouth theme with crazy animation nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-01-30 pkgs.python312Packages.txzmq Twisted bindings for ZeroMQ nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python313Packages.txzmq Twisted bindings for ZeroMQ nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python312Packages.python-xz Pure Python library for seeking within compressed xz files nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.python313Packages.python-xz Pure Python library for seeking within compressed xz files nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.typstPackages.exzellenz-tum-thesis_0_1_0 Customizable template for a thesis at the TU Munich nixos-unstable ??? nixpkgs-unstable 0.1.0 pkgs.tests.pkg-config.defaultPkgConfigPackages.liblzma Test whether xz-5.8.1 exposes pkg-config modules liblzma nixos-unstable ??? nixpkgs-unstable Package maintainers: 7 @7c6f434c Michael Raskin <7c6f434c@mail.ru> @mxmlnkn Maximilian Knespel @johnrtitor Masum Reza <masumrezarock100@gmail.com> @ip1981 Igor Pashev <pashev.igor@gmail.com> @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @womfoo Kranium Gikos Mendoza <kranium@gikos.net> @cherrypiejam Gongqi Huang
pkgs.xz General-purpose data compression software, successor of LZMA nixos-unstable ??? nixpkgs-unstable 5.8.1
pkgs.pxz Compression utility that runs LZMA compression of different parts on multiple cores simultaneously nixos-unstable ??? nixpkgs-unstable 4.999.9beta
pkgs.xzgv Picture viewer for X with a thumbnail-based selector nixos-unstable ??? nixpkgs-unstable 0.9.2
pkgs.haskellPackages.xz LZMA/XZ compression and decompression nixos-unstable ??? nixpkgs-unstable 5.6.3
pkgs.plymouth-proxzima-theme Techno Plymouth theme with crazy animation nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-01-30
pkgs.python312Packages.python-xz Pure Python library for seeking within compressed xz files nixos-unstable ??? nixpkgs-unstable 0.5.0
pkgs.python313Packages.python-xz Pure Python library for seeking within compressed xz files nixos-unstable ??? nixpkgs-unstable 0.5.0
pkgs.typstPackages.exzellenz-tum-thesis_0_1_0 Customizable template for a thesis at the TU Munich nixos-unstable ??? nixpkgs-unstable 0.1.0
pkgs.tests.pkg-config.defaultPkgConfigPackages.liblzma Test whether xz-5.8.1 exposes pkg-config modules liblzma nixos-unstable ??? nixpkgs-unstable
CVE-2024-2947 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Cockpit: command injection when deleting a sosreport with a crafted name A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer. cockpit * * pkgs.cockpit Web-based graphical interface for servers nixos-unstable ??? nixpkgs-unstable 346 Package maintainers: 1 @lucasew Lucas Eduardo Wendt <lucas59356@gmail.com>
CVE-2024-3019 8.8 HIGH CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Pcp: exposure of the redis server backend allows remote command execution via pmproxy A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer. pcp * * pkgs.pcp Command line peer-to-peer data transfer tool based on libp2p nixos-unstable ??? nixpkgs-unstable 0.4.0 pkgs.ncmpcpp Featureful ncurses based MPD client inspired by ncmpc nixos-unstable ??? nixpkgs-unstable 0.10.1 pkgs.libamqpcpp Library for communicating with a RabbitMQ server nixos-unstable ??? nixpkgs-unstable 4.3.27 pkgs.python312Packages.pcpp C99 preprocessor written in pure Python nixos-unstable ??? nixpkgs-unstable 1.30 pkgs.python313Packages.pcpp C99 preprocessor written in pure Python nixos-unstable ??? nixpkgs-unstable 1.30 Package maintainers: 5 @lovek323 Jason O'Conal <jason@oconal.id.au> @k0ral Koral <koral@mailoo.org> @MikePlayle Mike Playle <mike@mythik.co.uk> @Rakesh4G Rakesh Gupta <rakeshgupta4u@gmail.com> @MatthewCroughan Matthew Croughan <matt@croughan.sh>
pkgs.pcp Command line peer-to-peer data transfer tool based on libp2p nixos-unstable ??? nixpkgs-unstable 0.4.0
pkgs.ncmpcpp Featureful ncurses based MPD client inspired by ncmpc nixos-unstable ??? nixpkgs-unstable 0.10.1
pkgs.libamqpcpp Library for communicating with a RabbitMQ server nixos-unstable ??? nixpkgs-unstable 4.3.27
pkgs.python312Packages.pcpp C99 preprocessor written in pure Python nixos-unstable ??? nixpkgs-unstable 1.30
pkgs.python313Packages.pcpp C99 preprocessor written in pure Python nixos-unstable ??? nixpkgs-unstable 1.30
CVE-2024-30229 8.0 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability Deserialization of Untrusted Data vulnerability in GiveWP.This issue affects GiveWP: from n/a through 3.4.2. give =<3.4.2 pkgs.filegive Easy p2p file sending program nixos-unstable ??? nixpkgs-unstable 2022-05-29
CVE-2024-29815 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month ago WordPress WP Change Email Sender plugin < 1.3.0 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Change Email Sender allows Stored XSS.This issue affects WP Change Email Sender: from n/a before 1.3.0. wp-change-email-sender <1.3.0 pkgs.wordpressPackages.plugins.wp-change-email-sender nixos-unstable ??? nixpkgs-unstable 3.0
CVE-2024-29768 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month ago WordPress Astra theme <= 4.6.4 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4. astra =<4.6.4 pkgs.astral Tool for estimating an unrooted species tree given a set of unrooted gene trees nixos-unstable ??? nixpkgs-unstable 5.7.1 pkgs.akkuPackages.riastradh Libraries by Taylor Campbell ported to Chez Scheme nixos-unstable ??? nixpkgs-unstable 0.0.0-akku.16.9714b5c pkgs.python312Packages.astral Calculations for the position of the sun and the moon nixos-unstable ??? nixpkgs-unstable 3.2 pkgs.python313Packages.astral Calculations for the position of the sun and the moon nixos-unstable ??? nixpkgs-unstable 3.2 pkgs.gnomeExtensions.astra-monitor Astra Monitor is a cutting-edge, fully customizable, and performance-focused system monitoring extension for GNOME's top bar. It's an all-in-one solution for those seeking to keep a close eye on their system's performance metrics like CPU, GPU, RAM, disk usage, network statistics, and sensor readings. nixos-unstable ??? nixpkgs-unstable 51 pkgs.gnomeExtensions.astrapios-panel-menu A GNOME Shell Extension to add custom menu to panel nixos-unstable ??? nixpkgs-unstable 6 Package maintainers: 4 @flokli Florian Klink <flokli@flokli.de> @honnip Jung seungwoo <me@honnip.page> @bzizou Bruno Bzeznik <Bruno@bzizou.net> @TomaSajt TomaSajt
pkgs.astral Tool for estimating an unrooted species tree given a set of unrooted gene trees nixos-unstable ??? nixpkgs-unstable 5.7.1
pkgs.akkuPackages.riastradh Libraries by Taylor Campbell ported to Chez Scheme nixos-unstable ??? nixpkgs-unstable 0.0.0-akku.16.9714b5c
pkgs.python312Packages.astral Calculations for the position of the sun and the moon nixos-unstable ??? nixpkgs-unstable 3.2
pkgs.python313Packages.astral Calculations for the position of the sun and the moon nixos-unstable ??? nixpkgs-unstable 3.2
pkgs.gnomeExtensions.astra-monitor Astra Monitor is a cutting-edge, fully customizable, and performance-focused system monitoring extension for GNOME's top bar. It's an all-in-one solution for those seeking to keep a close eye on their system's performance metrics like CPU, GPU, RAM, disk usage, network statistics, and sensor readings. nixos-unstable ??? nixpkgs-unstable 51
pkgs.gnomeExtensions.astrapios-panel-menu A GNOME Shell Extension to add custom menu to panel nixos-unstable ??? nixpkgs-unstable 6