Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: grafanaPlugins.grafana-pyroscope-app

Found 22 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2024-11831
5.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 1 month ago by @anthonyroussel Activity log
  • Created automatic suggestion
  • @anthonyroussel removed
    4 packages
    • pcsclite
    • pcsctools
    • pcscliteWithPolkit
    • vpcs
Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

References

Affected products

pcs
ceph
  • *
pybind
grafana
libarrow
dotnet6.0
dotnet7.0
dotnet8.0
  • *
nodejs-webpack
quay/quay-rhel8
mta/mta-ui-rhel9
mta/mta-cli-rhel9
rh-dotnet60-dotnet
rhdh-hub-container
odf4/mcg-core-rhel8
odf4/mcg-core-rhel9
odh-dashboard-rhel8
rhdh/rhdh-hub-rhel9
devspaces/code-rhel8
rhacm2/console-rhel8
rhacm2/console-rhel9
serialize-javascript
  • <6.0.2
automation-controller
rhceph/rhceph-8-rhel9
  • *
aap-cloud-ui-container
odf4/odf-console-rhel9
  • *
odh-operator-container
openshift3/ose-console
devspaces/traefik-rhel8
odh-dashboard-container
rhdh-operator-container
odh-model-registry-rhel8
automation-eda-controller
devspaces/dashboard-rhel8
rhosdt/jaeger-agent-rhel8
rhosdt/jaeger-query-rhel8
discovery-server-container
3scale-amp-system-container
rhosdt/jaeger-ingester-rhel8
odf4/ocs-client-console-rhel9
  • *
odh-ml-pipelines-driver-rhel8
odh-notebook-controller-rhel8
rhosdt/jaeger-collector-rhel8
nodejs-uglifyjs-webpack-plugin
rhosdt/jaeger-all-in-one-rhel8
odh-ml-pipelines-launcher-rhel8
openshift-logging/kibana6-rhel8
rhosdt/jaeger-es-rollover-rhel8
odh-kf-notebook-controller-rhel8
nodejs-compression-webpack-plugin
openshift-service-mesh/kiali-rhel8
nodejs-css-minimizer-webpack-plugin
odf4/odf-multicluster-console-rhel8
odf4/odf-multicluster-console-rhel9
  • *
odh-ml-pipelines-api-server-v2-rhel8
rhosdt/jaeger-es-index-cleaner-rhel8
openshift4/ose-monitoring-plugin-rhel8
openshift4/ose-monitoring-plugin-rhel9
openshift-service-mesh/kiali-ossmc-rhel8
rhtpa/rhtpa-trustification-service-rhel9
advanced-cluster-security/rhacs-main-rhel8
  • *
odh-ml-pipelines-persistenceagent-v2-rhel8
openshift-pipelines/pipelines-hub-ui-rhel8
  • *
odh-ml-pipelines-scheduledworkflow-v2-rhel8
openshift-pipelines/pipelines-hub-api-rhel8
advanced-cluster-security/rhacs-roxctl-rhel8
advanced-cluster-security/rhacs-rhel8-operator
odh-data-science-pipelines-argo-argoexec-rhel8
ansible-automation-platform-24/lightspeed-rhel8
ansible-automation-platform-25/lightspeed-rhel8
advanced-cluster-security/rhacs-central-db-rhel8
advanced-cluster-security/rhacs-scanner-v4-rhel8
openshift-pipelines-console-plugin-rhel8-container
openshift-pipelines/pipelines-console-plugin-rhel8
  • *
openshift-pipelines/pipelines-console-plugin-rhel9
  • *
advanced-cluster-security/rhacs-scanner-v4-db-rhel8
openshift-pipelines/pipelines-hub-db-migration-rhel8
odh-data-science-pipelines-argo-workflowcontroller-rhel8
migration-toolkit-virtualization/mtv-console-plugin-rhel9
openshift-lightspeed-beta/lightspeed-console-plugin-rhel9

Matching in nixpkgs

pkgs.pcsx2

Playstation 2 emulator

  • nixos-unstable -

pkgs.rpcs3

PS3 emulator/debugger

  • nixos-unstable -

pkgs.pcstat

Page Cache stat: get page cache stats for files on Linux

  • nixos-unstable -

pkgs.grafana

Gorgeous metric viz, dashboards & editors for Graphite, InfluxDB & OpenTSDB

  • nixos-unstable -

pkgs.appcsxcad

Minimal Application using the QCSXCAD library

  • nixos-unstable -

pkgs.pcsx2-bin

Playstation 2 emulator (precompiled binary, repacked from official website)

  • nixos-unstable -

pkgs.grafanactl

Tool designed to simplify interaction with Grafana instances

  • nixos-unstable -

pkgs.baidupcs-go

Baidu Netdisk commandline client, mimicking Linux shell file handling commands

  • nixos-unstable -

pkgs.rpcsvc-proto

This package contains rpcsvc proto.x files from glibc, which are missing in libtirpc

  • nixos-unstable -

pkgs.grafana-alloy

Open source OpenTelemetry Collector distribution with built-in Prometheus pipelines and support for metrics, logs, traces, and profiles

  • nixos-unstable -

pkgs.pcsc-cyberjack

REINER SCT cyberJack USB chipcard reader user space driver

  • nixos-unstable -

pkgs.pcsc-scm-scl011

SCM Microsystems SCL011 chipcard reader user space driver

  • nixos-unstable -

pkgs.grafana-dash-n-grab

Grafana Dash-n-Grab (gdg) -- backup and restore Grafana dashboards, datasources, and other entities

  • nixos-unstable -

pkgs.grafanaPlugins.grafana-pyroscope-app

Integrate seamlessly with Pyroscope, the open-source continuous profiling platform, providing a smooth, query-less experience for browsing and analyzing profiling data

  • nixos-unstable -
Ignored packages (4)

pkgs.vpcs

Simple virtual PC simulator

  • nixos-unstable -

pkgs.pcsclite

Middleware to access a smart card using SCard API (PC/SC)

  • nixos-unstable -

pkgs.pcsctools

Tools used to test a PC/SC driver, card or reader

  • nixos-unstable -

Package maintainers

Untriaged
Permalink CVE-2024-22034
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months, 1 week ago
Crafted projects can overwrite special files in the .osc config directory

Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim

Affected products

osc
  • <1.9.0-150400.10.6.1
  • <1.9.0-1.1
  • <0.183.0-15.18.1

Matching in nixpkgs

pkgs.osc

Command line tool to access the system clipboard from anywhere using the ANSI OSC52 sequence

  • nixos-unstable -

pkgs.OSCAR

Software for reviewing and exploring data produced by CPAP and related machines used in the treatment of sleep apnea

  • nixos-unstable -

pkgs.oscar

Software for reviewing and exploring data produced by CPAP and related machines used in the treatment of sleep apnea

  • nixos-unstable -

pkgs.c-blosc

Blocking, shuffling and loss-less compression library

  • nixos-unstable -

pkgs.ergoscf

Quantum chemistry program for large-scale self-consistent field calculations

  • nixos-unstable -

pkgs.osc-cli

Official Outscale CLI providing connectors to Outscale API

  • nixos-unstable -

pkgs.oscclip

Program that allows to copy/paste from a terminal using osc-52 control sequences

  • nixos-unstable -

pkgs.xoscope

Oscilloscope through the sound card

  • nixos-unstable -

pkgs.badtouch

Scriptable network authentication cracker

  • nixos-unstable -

pkgs.c-blosc2

Fast, compressed, persistent binary data store library for C

pkgs.octoscan

Static vulnerability scanner for GitHub action workflows

  • nixos-unstable -

pkgs.oscavmgr

Face tracking & utilities for Resonite and VRChat

  • nixos-unstable -

pkgs.talosctl

CLI for out-of-band management of Kubernetes nodes created by Talos

  • nixos-unstable -

pkgs.touchosc

Next generation modular control surface

pkgs.cytoscape

General platform for complex network analysis and visualization

  • nixos-unstable -

pkgs.picoscope

Oscilloscope application that works with all PicoScope models

pkgs.pyroscope

Continuous profiling platform; debug performance issues down to a single line of code

  • nixos-unstable -

pkgs.authoscope

Scriptable network authentication cracker

  • nixos-unstable -

pkgs.diffoscope

Perform in-depth comparison of files, archives, and directories

  • nixos-unstable -

pkgs.hdf5-blosc

Filter for HDF5 that uses the Blosc compressor

  • nixos-unstable -

pkgs.nethoscope

Listen to your network traffic

  • nixos-unstable -

pkgs.microscheme

Scheme subset for Atmel microcontrollers

  • nixos-unstable -

pkgs.exoscale-cli

Command-line tool for everything at Exoscale: compute, storage, dns

  • nixos-unstable -

pkgs.vokoscreen-ng

User friendly Open Source screencaster for Linux and Windows

  • nixos-unstable -

pkgs.mpvScripts.uosc

Feature-rich minimalist proximity-based UI for MPV player

  • nixos-unstable -

pkgs.iio-oscilloscope

GTK+ based oscilloscope application for interfacing with various IIO devices

  • nixos-unstable -

pkgs.diffoscopeMinimal

Perform in-depth comparison of files, archives, and directories

  • nixos-unstable -

pkgs.grafanaPlugins.grafana-pyroscope-app

Integrate seamlessly with Pyroscope, the open-source continuous profiling platform, providing a smooth, query-less experience for browsing and analyzing profiling data

  • nixos-unstable -

Package maintainers