Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2024-5953
5.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): ADJACENT_NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 6 months ago
389-ds-base: malformed userpassword hash may cause denial of service

A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.

References

Affected products

389-ds:1.4
  • *
389-ds-base
  • *
redhat-ds:11
  • *
redhat-ds:12
  • *
389-ds:1.4/389-ds-base
redhat-ds:11/389-ds-base
redhat-ds:12/389-ds-base

Matching in nixpkgs

pkgs._389-ds-base

Enterprise-class Open Source LDAP server for Linux

  • nixos-unstable -

Package maintainers

Permalink CVE-2024-25142
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 6 months ago
Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.

Affected products

apache-airflow
  • <2.9.2

Matching in nixpkgs

pkgs.apache-airflow

Programmatically author, schedule and monitor data pipelines

  • nixos-unstable -

Package maintainers

Permalink CVE-2024-2698
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 6 months ago
Freeipa: delegation rules allow a proxy service to impersonate any user to access another target service

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the check_allowed_to_delegate() function: If the target service argument is NULL, then it means the KDC is probing for general constrained delegation rules and not checking a specific S4U2Proxy request. In FreeIPA 4.11.0, the behavior of ipadb_match_acl() was modified to match the changes from upstream MIT Kerberos 1.20. However, a mistake resulting in this mechanism applies in cases where the target service argument is set AND where it is unset. This results in S4U2Proxy requests being accepted regardless of whether or not there is a matching service delegation rule.

References

Affected products

ipa
  • *
freeipa
  • <4.11.2
  • <4.12.1
idm:DL1
  • *
idm:client/ipa

Matching in nixpkgs

pkgs.ipam

Cli based IPAM written in Go with PowerDNS support

pkgs.tipa

Phonetic font for TeX

  • nixos-unstable -

pkgs.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.freeipa

Identity, Policy and Audit system

  • nixos-unstable -

pkgs.ipafont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.ipatool

Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

  • nixos-unstable -

pkgs.codipack

Fast gradient evaluation in C++ based on Expression Templates

  • nixos-unstable -

pkgs.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.iniparser

Free standalone ini file parsing library

  • nixos-unstable -

pkgs.ipaexfont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.multipass

Ubuntu VMs on demand for any workstation

  • nixos-unstable -

pkgs.nipap-cli

Neat IP Address Planner CLI

  • nixos-unstable -

pkgs.nipap-www

Neat IP Address Planner CLI, web UI

  • nixos-unstable -

pkgs.uriparser

Strictly RFC 3986 compliant URI parsing library

  • nixos-unstable -

pkgs.frangipanni

Convert lines of text into a tree structure

  • nixos-unstable -

Package maintainers

Permalink CVE-2024-3183
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months ago
Freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal key directly. For user principals, this key is a hash of a public per-principal randomly-generated salt and the user’s password. If a principal is compromised it means the attacker would be able to retrieve tickets encrypted to any principal, all of them being encrypted by their own key directly. By taking these tickets and salts offline, the attacker could run brute force attacks to find character strings able to decrypt tickets when combined to a principal salt (i.e. find the principal’s password).

References

Affected products

ipa
  • *
freeipa
  • ==4.12.1
idm:DL1
  • *

Matching in nixpkgs

pkgs.ipam

Cli based IPAM written in Go with PowerDNS support

pkgs.tipa

Phonetic font for TeX

  • nixos-unstable -

pkgs.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.freeipa

Identity, Policy and Audit system

  • nixos-unstable -

pkgs.ipafont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.ipatool

Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

  • nixos-unstable -

pkgs.codipack

Fast gradient evaluation in C++ based on Expression Templates

  • nixos-unstable -

pkgs.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.iniparser

Free standalone ini file parsing library

  • nixos-unstable -

pkgs.ipaexfont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.multipass

Ubuntu VMs on demand for any workstation

  • nixos-unstable -

pkgs.nipap-cli

Neat IP Address Planner CLI

  • nixos-unstable -

pkgs.nipap-www

Neat IP Address Planner CLI, web UI

  • nixos-unstable -

pkgs.uriparser

Strictly RFC 3986 compliant URI parsing library

  • nixos-unstable -

pkgs.frangipanni

Convert lines of text into a tree structure

  • nixos-unstable -

Package maintainers

Permalink CVE-2024-5742
4.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months ago
Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

References

Affected products

nano
  • *

Matching in nixpkgs

pkgs.nano

Small, user-friendly console text editor

  • nixos-unstable -

pkgs.nanomq

Ultra-lightweight and blazing-fast MQTT broker for IoT edge

  • nixos-unstable -

pkgs.nanopb

Protocol Buffers with small code size

pkgs.nanorc

Improved Nano Syntax Highlighting Files

pkgs.nanodbc

Small C++ wrapper for the native C ODBC API

  • nixos-unstable -

pkgs.nanomsg

Socket library that provides several common communication patterns

  • nixos-unstable -

pkgs.nanotts

Speech synthesizer commandline utility that improves pico2wave, included with SVOX PicoTTS

pkgs.nanobench

Simple, fast, accurate single-header microbenchmarking functionality for C++11/14/17/20

  • nixos-unstable -

pkgs.nanoemoji

Wee tool to build color fonts

  • nixos-unstable -

pkgs.nanoflann

Header only C++ library for approximate nearest neighbor search

  • nixos-unstable -

pkgs.fusee-nano

Minimalist re-implementation of the Fusée Gelée exploit

pkgs.nano-wallet

Wallet for Nano cryptocurrency

  • nixos-unstable -

pkgs.nanovna-saver

Tool for reading, displaying and saving data from the NanoVNA

  • nixos-unstable -

pkgs.nanoboyadvance

Cycle-accurate Nintendo Game Boy Advance emulator

  • nixos-unstable -

pkgs.python312Packages.pynanoleaf

Python3 wrapper for the Nanoleaf API, capable of controlling both Nanoleaf Aurora and Nanoleaf Canvas

  • nixos-unstable -

pkgs.python313Packages.pynanoleaf

Python3 wrapper for the Nanoleaf API, capable of controlling both Nanoleaf Aurora and Nanoleaf Canvas

  • nixos-unstable -

Package maintainers

Permalink CVE-2024-5154
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months ago
Cri-o: malicious container can create symlink on host

A flaw was found in cri-o. A malicious container can create a symbolic link pointing to an arbitrary directory or file on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

References

Affected products

cri-o
  • <1.28.7
  • <1.30.1
  • <1.29.5
  • *
rhcos
  • *
conman
conmon
kernel
  • *
openshift
  • *
container-tools:rhel8/podman

Matching in nixpkgs

pkgs.cri-o

Open Container Initiative-based implementation of the Kubernetes Container Runtime Interface

  • nixos-unstable -

pkgs.cri-o-unwrapped

Open Container Initiative-based implementation of the Kubernetes Container Runtime Interface

  • nixos-unstable -

Package maintainers

Permalink CVE-2024-34768
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 6 months ago
WordPress Fastly plugin <= 1.2.25 - Broken Access Control vulnerability

Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

Affected products

fastly
  • =<1.2.25

Matching in nixpkgs

pkgs.fastly

Command line tool for interacting with the Fastly API

  • nixos-unstable -

Package maintainers

Permalink CVE-2023-25799
8.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilities

Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.

Affected products

tutor
  • =<2.1.8

Matching in nixpkgs

Package maintainers

Permalink CVE-2024-32779
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 6 months ago
WordPress Vision – Image Map Builder plugin <= 1.7.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Avirtum Vision Interactive.This issue affects Vision Interactive: from n/a through 1.7.1.

Affected products

vision
  • =<1.7.1

Matching in nixpkgs

pkgs.envision

UI for building, configuring and running Monado, the open source OpenXR runtime (with build environment)

  • nixos-unstable -

pkgs.television

Blazingly fast general purpose fuzzy finder TUI

  • nixos-unstable -

pkgs.autorevision

Extracts revision metadata from your VCS repository

  • nixos-unstable -

pkgs.photonvision

Free, fast, and easy-to-use computer vision solution for the FIRST Robotics Competition

pkgs.envision-unwrapped

UI for building, configuring and running Monado, the open source OpenXR runtime

  • nixos-unstable -

pkgs.rocmPackages.mivisionx

Set of comprehensive computer vision and machine intelligence libraries, utilities, and applications

  • nixos-unstable -

pkgs.thin-provisioning-tools

Suite of tools for manipulating the metadata of the dm-thin device-mapper target

  • nixos-unstable -

pkgs.rocmPackages_6.mivisionx

Set of comprehensive computer vision and machine intelligence libraries, utilities, and applications

  • nixos-unstable -

pkgs.rocmPackages.mivisionx-cpu

Set of comprehensive computer vision and machine intelligence libraries, utilities, and applications

  • nixos-unstable -

pkgs.rocmPackages.mivisionx-hip

Set of comprehensive computer vision and machine intelligence libraries, utilities, and applications

  • nixos-unstable -

pkgs.rocmPackages_6.mivisionx-cpu

Set of comprehensive computer vision and machine intelligence libraries, utilities, and applications

  • nixos-unstable -

pkgs.rocmPackages_6.mivisionx-hip

Set of comprehensive computer vision and machine intelligence libraries, utilities, and applications

  • nixos-unstable -
Permalink CVE-2024-35711
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 6 months ago
WordPress Event theme <= 1.2.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Freesia Event allows Stored XSS.This issue affects Event: from n/a through 1.2.2.

Affected products

event
  • =<1.2.2

Matching in nixpkgs

pkgs.tevent

Event system based on the talloc memory management library

  • nixos-unstable -

pkgs.direvent

Directory event monitoring daemon

  • nixos-unstable -

pkgs.eventlog

Syslog event logger library

  • nixos-unstable -

pkgs.libevent

Event notification library

  • nixos-unstable -

pkgs.lvm2_vdo

Tools to support Logical Volume Management (LVM) on Linux

pkgs.netevent

Share linux event devices with other machines

pkgs.eventstat

Simple monitoring of system events

pkgs.lvm2_dmeventd

Tools to support Logical Volume Management (LVM) on Linux

pkgs.seventeenlands

Client for passing relevant events from MTG Arena logs to the 17Lands REST endpoint, also known as mtga-log-client

  • nixos-unstable -

pkgs.aws-c-event-stream

C99 implementation of the vnd.amazon.eventstream content-type

  • nixos-unstable -

pkgs.php81Extensions.event

Efficiently schedule I/O, time and signal based events using the best I/O notification mechanism available

  • nixos-unstable -

pkgs.php82Extensions.event

Efficiently schedule I/O, time and signal based events using the best I/O notification mechanism available

  • nixos-unstable -

pkgs.php83Extensions.event

Efficiently schedule I/O, time and signal based events using the best I/O notification mechanism available

  • nixos-unstable -

pkgs.php84Extensions.event

Efficiently schedule I/O, time and signal based events using the best I/O notification mechanism available

  • nixos-unstable -

Package maintainers