Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-jh6x-7xfg-9cq2
  • Maven/org.opencastproject:opencast-elasticsearch-impl
Searching Opencast may cause a denial of service 8 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2x2g-32r7-p4x8
  • Maven/org.apache.kafka:kafka-clients
Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider yesterday
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-vggm-3478-vm5m
  • Maven/org.graylog:graylog-parent
Graylog concurrent PDF report rendering can leak other users' reports 2 days ago
  • Fix available
  • Severity - 7.1 (High)
GHSA-f632-9449-3j4w
  • Maven/org.apache.tomcat:tomcat-jasper
Apache Tomcat - XSS in generated JSPs 2 days ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-qvf5-hvjx-wm27
  • Maven/org.apache.tomcat.embed:tomcat-embed-core
  • Maven/org.apache.tomcat:tomcat-coyote
Apache Tomcat Request and/or response mix-up 2 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-xcpr-7mr4-h4xq
  • Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat - Authentication Bypass 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-w3c8-7r8f-9jp8
  • Maven/org.springframework:spring-webmvc
Spring MVC controller vulnerable to a DoS attack 3 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-3jrv-jgp8-45v3
  • Maven/io.undertow:undertow-core
Undertow incorrectly parses cookies 3 days ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-hvw5-3mgw-7rcf
  • Maven/io.debezium:debezium-connector-mysql
  • Maven/io.debezium:debezium-connector-sqlserver
  • Maven/io.debezium:debezium-core
Debezium database connector has a script injection vulnerability 3 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-pg82-9w35-3w3r
  • Maven/org.fitnesse:fitnesse
FitNesse Cross-site scripting 6 days ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-q297-5ff8-hc92
  • Maven/org.fitnesse:fitnesse
FitNesse Path Traversal 6 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7845-crfj-phc4
  • Maven/io.jenkins.plugins:shared-library-version-override
Script security bypass vulnerability in Jenkins Shared Library Version Override Plugin 13 Nov
  • Fix available
  • Severity - 8.8 (High)
GHSA-8886-8v27-85j8
  • Maven/org.jenkins-ci.plugins:authorize-project
Stored XSS vulnerability in Jenkins Authorize Project Plugin 13 Nov
  • Fix available
  • Severity - 8.0 (High)
GHSA-h23j-73ww-7594
  • Maven/org.jenkins-ci.plugins:oic-auth
Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin 13 Nov
  • Fix available
  • Severity - 8.8 (High)
GHSA-jv82-75fh-23r7
  • Maven/org.jenkins-ci.plugins:script-security
Missing permission check in Jenkins Script Security Plugin 13 Nov
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-mrpr-vr82-x88r
  • Maven/org.jenkins-ci.plugins.workflow:workflow-cps
Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin 13 Nov
  • Fix available
  • Severity - 8.0 (High)