Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: mastodon-archive

Found 7 matching suggestions

created 2 weeks, 6 days ago
Mastodon may allow a remote suspension bypass

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appear in timelines if boosted. Furthermore, under certain circumstances, previously-unknown posts from suspended users can be processed. This issue allows old posts from suspended users to occasionally end up on timelines on all Mastodon versions. Additionally, on Mastodon versions from v4.5.0 to v4.5.4, v4.4.5 to v4.4.11, v4.3.13 to v4.3.17, and v4.2.26 to v4.2.29, remote suspended users can partially bypass the suspension to get new posts in. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.12
  • ==< 4.3.18
  • ==>= 4.5.0, < 4.5.5

Matching in nixpkgs

created 2 weeks, 6 days ago
Mastodon missing length limits on list names, filter names, and filter keywords

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set an arbitrarily long string as the name or keyword. Any local user can abuse the list or filter fields to cause disproportionate storage and computing resource usage. They can additionally cause their own web interface to be unusable, although they must intentionally do this to themselves or unknowingly approve a malicious API client. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.12
  • ==< 4.3.18
  • ==>= 4.5.0, < 4.5.5

Matching in nixpkgs

created 2 weeks, 6 days ago
Mastodon vulnerable to Denial of Service from a single post (client/server)

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll options for remote posts, allowing attackers to create polls with a very large amount of options, greatly increasing resource consumption. Depending on the number of poll options, an attacker can cause disproportionate resource usage in both Mastodon servers and clients, potentially causing Denial of Service either server-side or client-side. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.12
  • ==< 4.3.18
  • ==>= 4.5.0, < 4.5.5

Matching in nixpkgs

created 2 weeks, 6 days ago
Mastodon has insufficient access control to push notification settings

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user's push subscription by guessing or obtaining the numeric subscription id. This can be used to disrupt push notifications for other users and also leaks the web push subscription endpoint. Any user with a web push subscription is impacted, because another authenticated user can tamper with their push subscription settings if they can guess or obtain the subscription id. This allows an attacker to disrupt push notifications by changing the policy (whether to filter notifications from non-followers or non-followed users) and subscribed notification types of their victims. Additionally, the endpoint returns the subscription object, which includes the push notification endpoint for this subscription, but not its keypair. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.12
  • ==< 4.3.18
  • ==>= 4.5.0, < 4.5.5

Matching in nixpkgs

created 4 months, 3 weeks ago
Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

Affected products

hive
  • =<1.1.16
rhacm2/cluster-backup-rhel8-operator
rhacm2/cluster-backup-rhel9-operator
multicluster-engine/multicloud-manager-rhel8

Matching in nixpkgs

pkgs.hivex

Windows registry hive extraction library

  • nixos-unstable -

pkgs.enchive

Encrypted personal archives

  • nixos-unstable -

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

  • nixos-unstable -

pkgs.hivemind

Process manager for Procfile-based applications

  • nixos-unstable -

pkgs.zarchive

File archive format supporting random-access reads

  • nixos-unstable -

pkgs.xarchiver

GTK frontend to 7z,zip,rar,tar,bzip2, gzip,arj, lha, rpm and deb (open and extract only)

pkgs.ytarchive

Garbage Youtube livestream downloader

  • nixos-unstable -

pkgs.disarchive

Disassemble software into data and metadata

  • nixos-unstable -

pkgs.fsarchiver

File system archiver for linux

  • nixos-unstable -

pkgs.libarchive

Multi-format archive and compression library

  • nixos-unstable -

pkgs.tg-archive

Tool for exporting Telegram group chats into static websites like mailing list archives

  • nixos-unstable -

pkgs.archivemount

Gateway between FUSE and libarchive: allows mounting of cpio, .tar.gz, .tar.bz2 archives

  • nixos-unstable -
    • nixpkgs-unstable 1b

pkgs.fuse-archive

Serve an archive or a compressed file as a read-only FUSE file system

  • nixos-unstable -

pkgs.jpeg-archive

Utilities for archiving photos for saving to long term storage or serving over the web

  • nixos-unstable -

pkgs.web-archives

Web archives reader offering the ability to browse offline millions of articles

  • nixos-unstable -

pkgs.hivelytracker

Chip music tracker based upon the AHX format

  • nixos-unstable -

pkgs.libarchive-qt

Qt based archiving solution with libarchive backend

  • nixos-unstable -

pkgs.lparchive2epub

Transform any LP from lparchive into an epub document

  • nixos-unstable -

pkgs.internetarchive

Python and Command-Line Interface to Archive.org

  • nixos-unstable -

pkgs.kodiPackages.archive_tool

Set of common python functions to work with the Kodi archive virtual file system (vfs) binary addons

  • nixos-unstable -

Package maintainers

created 4 months, 3 weeks ago
Openshift-dedicated: hive: hibernation controller denial of service

A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive timespan for the spec.hibernateAfter value. If a ClusterSync.hiveinternal.openshift.io/v1alpha1 resource is also created, the hive hibernation controller will enter the reconciliation loop leading to a panic when accessing a non-existing field in the ClusterDeployment’s status section, resulting in a denial of service.

Affected products

hive
  • <126c7eb43aa55a008b8f0cf594e7bd18086841eb

Matching in nixpkgs

pkgs.hivex

Windows registry hive extraction library

  • nixos-unstable -

pkgs.enchive

Encrypted personal archives

  • nixos-unstable -

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

  • nixos-unstable -

pkgs.hivemind

Process manager for Procfile-based applications

  • nixos-unstable -

pkgs.zarchive

File archive format supporting random-access reads

  • nixos-unstable -

pkgs.xarchiver

GTK frontend to 7z,zip,rar,tar,bzip2, gzip,arj, lha, rpm and deb (open and extract only)

pkgs.ytarchive

Garbage Youtube livestream downloader

  • nixos-unstable -

pkgs.disarchive

Disassemble software into data and metadata

  • nixos-unstable -

pkgs.fsarchiver

File system archiver for linux

  • nixos-unstable -

pkgs.libarchive

Multi-format archive and compression library

  • nixos-unstable -

pkgs.tg-archive

Tool for exporting Telegram group chats into static websites like mailing list archives

  • nixos-unstable -

pkgs.archivemount

Gateway between FUSE and libarchive: allows mounting of cpio, .tar.gz, .tar.bz2 archives

  • nixos-unstable -
    • nixpkgs-unstable 1b

pkgs.fuse-archive

Serve an archive or a compressed file as a read-only FUSE file system

  • nixos-unstable -

pkgs.jpeg-archive

Utilities for archiving photos for saving to long term storage or serving over the web

  • nixos-unstable -

pkgs.web-archives

Web archives reader offering the ability to browse offline millions of articles

  • nixos-unstable -

pkgs.hivelytracker

Chip music tracker based upon the AHX format

  • nixos-unstable -

pkgs.libarchive-qt

Qt based archiving solution with libarchive backend

  • nixos-unstable -

pkgs.lparchive2epub

Transform any LP from lparchive into an epub document

  • nixos-unstable -

pkgs.internetarchive

Python and Command-Line Interface to Archive.org

  • nixos-unstable -

pkgs.kodiPackages.archive_tool

Set of common python functions to work with the Kodi archive virtual file system (vfs) binary addons

  • nixos-unstable -

Package maintainers

created 4 months, 3 weeks ago
Registry-support: decompress can delete files outside scope via relative paths

A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.

Affected products

odo
registry-support
  • ==1.16.2
openshift4/ose-console

Matching in nixpkgs

pkgs.odo

Developer-focused CLI for OpenShift and Kubernetes

  • nixos-unstable -

pkgs.todo

Simple todo cli program written in rust

  • nixos-unstable -

pkgs.ctodo

Simple ncurses-based task list manager

  • nixos-unstable -

pkgs.godot

Free and Open Source 2D and 3D game engine

pkgs.diodon

Aiming to be the best integrated clipboard manager for the Unity desktop

  • nixos-unstable -

pkgs.godot3

Free and Open Source 2D and 3D game engine (X11 tools)

  • nixos-unstable -

pkgs.komodo

Tool to build and deploy software on many servers

  • nixos-unstable -

pkgs.devtodo

Hierarchical command-line task manager

  • nixos-unstable -

pkgs.robodoc

Documentation Extraction Tool

pkgs.todoman

Standards-based task manager based on iCalendar

  • nixos-unstable -

pkgs.comodoro

CLI to manage your time

  • nixos-unstable -

pkgs.dadadodo

Markov chain-based text generator

  • nixos-unstable -

pkgs.mastodon

Self-hosted, globally interconnected microblogging software based on ActivityPub

  • nixos-unstable -

pkgs.todofi-sh

Todo-txt + Rofi = Todofi.sh

  • nixos-unstable -

pkgs.podofo_0_9

Library to work with the PDF file format

  • nixos-unstable -

pkgs.podofo_1_0

Library to work with the PDF file format

  • nixos-unstable -

pkgs.sleek-todo

Todo manager based on todo.txt syntax

  • nixos-unstable -

pkgs.godot3-mono

Free and Open Source 2D and 3D game engine (mono build)

  • nixos-unstable -

pkgs.podofo_0_10

Library to work with the PDF file format

  • nixos-unstable -

pkgs.godotpcktool

Standalone tool for extracting and creating Godot .pck files

  • nixos-unstable -

pkgs.libre-bodoni

Bodoni fonts adapted for today's web requirements

  • nixos-unstable -

pkgs.pomodoro-gtk

Simple and intuitive timer application (also named Planytimer)

  • nixos-unstable -

pkgs.autodock-vina

One of the fastest and most widely used open-source docking engines

  • nixos-unstable -

pkgs.godot3-server

Free and Open Source 2D and 3D game engine (server)

  • nixos-unstable -

pkgs.koodousfinder

Tool to allows users to search for and analyze Android apps

  • nixos-unstable -

pkgs.gnome-pomodoro

Time management utility for GNOME based on the pomodoro technique

  • nixos-unstable -

pkgs.godot3-headless

Free and Open Source 2D and 3D game engine (headless)

  • nixos-unstable -

pkgs.openpomodoro-cli

Command-line Pomodoro tracker which uses the Open Pomodoro Format

  • nixos-unstable -

pkgs.godot3-mono-server

Free and Open Source 2D and 3D game engine (mono server)

  • nixos-unstable -

pkgs.godot3-debug-server

Free and Open Source 2D and 3D game engine (debug server)

  • nixos-unstable -

pkgs.gnomeExtensions.todo

Lightweight and user-friendly extension designed to help you manage your tasks efficiently. With a minimalistic interface, it allows you to add, modify, and delete tasks effortlessly. No complicated settings, just pure productivity!

  • nixos-unstable -
    • nixpkgs-unstable 5

Package maintainers