Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: graphql-language-service-cli

Found 2 matching suggestions

created 3 weeks ago
Hasura GraphQL 1.3.3 - Remote Code Execution

Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM functionality.

Affected products

GraphQL
  • ==1.3.3

Matching in nixpkgs

created 4 months, 3 weeks ago
WordPress Service plugin <= 1.0.4 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in serviceonline Service allows Blind SQL Injection.This issue affects Service: from n/a through 1.0.4.

Affected products

service
  • =<1.0.4

Matching in nixpkgs

pkgs.lk-jwt-service

Minimal service to issue LiveKit JWTs for MatrixRTC

  • nixos-unstable -

pkgs.accountsservice

D-Bus interface for user account query and manipulation

pkgs.service-wrapper

Convenient wrapper for the systemctl commands, borrow from Ubuntu

  • nixos-unstable -

pkgs.lomiri.hfd-service

DBus-activated service that manages human feedback devices such as LEDs and vibrators on mobile devices

  • nixos-unstable -

pkgs.java-service-wrapper

Enables a Java Application to be run as a Windows Service or Unix Daemon

  • nixos-unstable -

Package maintainers