Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Low Security Advisories

Browse all Security Advisories for Low

Loading...
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJ4bXItYzlqbS03bW04
Exposure of Sensitive Information to an Unauthorized Actor in Apache hive
Ecosystems: maven
Packages: org.apache.hive:hive-service, org.apache.hive:hive-exec, org.apache.hive:hive
Source: GitHub Advisory Database
Blast Radius: 12.9
Published: almost 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA2MzkteHh2NS1qMzgz
Incorrect Permission Assignment for Critical Resource in Apache hive
Ecosystems: maven
Packages: org.apache.hive:hive-service, org.apache.hive:hive-exec, org.apache.hive:hive
Source: GitHub Advisory Database
Blast Radius: 12.9
Published: almost 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc0eDktNGY1eC04amo4
Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
Ecosystems: maven
Packages: org.apache.hive:hive-exec, org.apache.hive:hive-service, org.apache.hive:hive
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZqcW0tMjQ2Yy1td3Fn
In Bouncy Castle JCE Provider the other party DH public key is not fully validated
Ecosystems: maven
Packages: org.bouncycastle:bcprov-jdk15, org.bouncycastle:bcprov-jdk14
Source: GitHub Advisory Database
Blast Radius: 11.1
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXF3OHctMnhjcC14ZzU5
Insecure use of temporary files in Phusion passenger
Ecosystems: rubygems
Packages: passenger
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM3ajctcDVqcS0yNmZm
Insecure use of temporary files in passenger
Ecosystems: rubygems
Packages: passenger
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ4d3YtOTUzcC03cXBm
Phusion Passenger allows remote attackers to spoof headers
Ecosystems: rubygems
Packages: passenger
Source: GitHub Advisory Database
Blast Radius: 13.0
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRxNTMtZnFoYy1jcjQ2
ember-source Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: ember-source
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWd4cGotY3g3Zy04NThj
Regular Expression Denial of Service in debug
Ecosystems: npm
Packages: debug
Source: GitHub Advisory Database
Blast Radius: 22.8
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdtamYtanBqai05ZjNq
RuboCop gem Insecure use of /tmp
Ecosystems: rubygems
Packages: rubocop
Source: GitHub Advisory Database
Blast Radius: 16.7
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ4NDYtN3Jydi1tNGg4
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Ecosystems: rubygems
Packages: sqlite3-ruby
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM1cXEtZzY3My01cDQ5
Puppet allows local users to overwrite arbitrary files via a symlink attack
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ4ZjYtdzltcC05NWht
Puppet supports use of IP addresses in certnames without warning of potential risks
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc4OW0tM3dqdy1oODU3
Puppet vulnerable to Path Traversal
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThqeGotOXI1Zi13M20y
Puppet allows local users to obtain sensitive configuration information
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZxcnItcnJ3Zy02OXB2
Local API Login Credentials Disclosure in paratrooper-pingdom
Ecosystems: rubygems
Packages: paratrooper-pingdom
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3ZzQtOTNjNi0zaDQy
Directory Traversal in send
Ecosystems: npm
Packages: send
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk1OWotNWc5di0zZnBx
Paratrooper-newrelic Exposes of Sensitive Information to an Unauthorized Actor
Ecosystems: rubygems
Packages: paratrooper-newrelic
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA2OTItN21tMy0zZnhn
actionpack is vulnerable to remote bypass authentication
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 22.0
Published: almost 7 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW14OWYtdzhxcS1xNWpm
rest-client allows local users to obtain sensitive information by reading the log
Ecosystems: rubygems
Packages: rest-client
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Statistics
Advisories: 20,351
Packages: 8,931
Repositories: 496
Ecosystems: 12
Filter by Package
tensorflow-gpu 109 tensorflow-cpu 109 tensorflow 109 concrete5/concrete5 19 moodle/moodle 17 github.com/mattermost/mattermost/server/v8 14 typo3/cms 13 shopware/platform 12 phpmyadmin/phpmyadmin 10 shopware/core 10 nova 9 org.apache.tomcat:tomcat 9 org.jenkins-ci.main:jenkins-core 9 vyper 7 wasmtime 6 undici 6 ethyca-fides 6 puppet 6 Umbraco.CMS 6 org.keycloak:keycloak-services 6 silverstripe/framework 5 magento/community-edition 5 sweetalert2 5 github.com/authzed/spicedb 5 actionpack 5 rack 5 elliptic 5 typo3/cms-core 5 october/backend 5 k8s.io/kubernetes 5 helm.sh/helm/v3 5 baserproject/basercms 5 github.com/mattermost/mattermost-server/v6 4 zenml 4 electron 4 github.com/cilium/cilium 4 shopware/shopware 4 com.vaadin:flow-server 4 helm.sh/helm 4 simplesamlphp/simplesamlphp 4 symfony/symfony 3 bin-links 3 org.apache.hive:hive 3 mattermost-desktop 3 github.com/opencontainers/runc 3 go.etcd.io/etcd/v3 3 github.com/cosmos/cosmos-sdk 3 org.apache.hive:hive-exec 3 org.apache.hive:hive-service 3 @openzeppelin/contracts-upgradeable 3 ckb 3 com.vaadin:vaadin-bom 3 nautobot 3 ansible 3 typo3/cms-backend 3 cryptography 3 node-forge 3 glance 3 matrix-synapse 3 wagtail 3 org.graylog2:graylog2-server 3 passenger 3 github.com/mattermost/mattermost-server 3 vantage6 3 horizon 2 freewvs 2 github.com/hashicorp/nomad 2 statamic/cms 2 Zope 2 github.com/goharbor/harbor 2 github.com/nats-io/nats-server/v2 2 github.com/answerdev/answer 2 salt 2 @openzeppelin/contracts 2 @apollo/server 2 tools.devnull:build-notifications 2 org.jenkins-ci.plugins:azure-ad 2 org.jenkins-ci.plugins:mercurial 2 org.jenkins-ci.plugins:bigpanda-jenkins 2 org.keycloak:keycloak-ldap-federation 2 activesupport 2 org.jenkins-ci.plugins:wso2id-oauth 2 org.jenkins-ci.plugins:artifactory 2 com.ruoyi:ruoyi 2 parse-server 2 cargo 2 keystone 2 flarum/core 2 Nova 2 org.jenkins-ci.plugins:repository-connector 2 OctoPrint 2 go.etcd.io/etcd/client/v3 2 symfony/security-http 2 github.com/ntbosscher/gobase 2 langchain 2 microweber/microweber 2 plone 2 admidio/admidio 2 org.eclipse.jetty:jetty-servlets 2 org.eclipse.jetty:jetty-http 2 gradio 2 librenms/librenms 2 agnai 2 Flask-Security-Too 2 Flask-AppBuilder 2 tribalsystems/zenario 2 github.com/hashicorp/vault 2 org.bouncycastle:bcprov-jdk14 2 ceph-deploy 2 october/cms 2 apache-airflow 2 sequoia-openpgp 2 vodozemac 2 org.eclipse.jetty:jetty-server 2 next-auth 2 github.com/mattermost/mattermost-plugin-jira 2 github.com/cometbft/cometbft 2 s2n-quic 2 github.com/mutagen-io/mutagen 2 typo3/cms-install 2 aiohttp 2 grumpydictator/firefly-iii 2 sylius/sylius 2 com.inedo.proget:inedo-proget 2 github.com/sigstore/cosign 2 org.jenkins-ci.plugins:ec2 2 github.com/containerd/containerd 2 node-ipc 2 craftcms/cms 2 org.apache.activemq:activemq-parent 2 braces 2 tuf 2 typo3/cms-frontend 2 org.apache.hadoop:hadoop-common 2 ezsystems/ezplatform-kernel 2 ezsystems/ezpublish-kernel 2 angular 2 org.xwiki.platform:xwiki-platform-oldcore 2 winter/wn-backend-module 2 github.com/docker/docker 2 october/system 2 gilacms/gila 2 com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer 1 fast-csv 1 @fast-csv/parse 1 tlslite-ng 1 vega 1 tinymce 1 prestashop/productcomments 1 atty 1 com.coravy.hudson.plugins.github:github 1 audited 1 dynamodb-encryption-sdk 1 govuk_tech_docs 1 struts:struts 1 SafeURL-Python 1 org.apache.druid.extensions:druid-pac4j 1 shamir 1 matrix-react-sdk 1 opencart/opencart 1 auth0-lock 1 markdown 1 org.jenkins-ci.plugins:application-director-plugin 1 org.jenkins-ci.plugins:assembla 1 org.jenkins-ci.plugins:resource-disposer 1 yourls/yourls 1 bitlyshortener 1 org.apache.activemq:activemq-openwire-generator 1 RPLY 1 showdown 1 personnummer/personnummer 1 github.com/rancher/rancher 1 github.com/tektoncd/pipeline 1 npm-user-validate 1 webpack-subresource-integrity 1 django-registration 1 aws-encryption-sdk-cli 1 loggerhead 1 org.apache.druid:druid 1 go.mozilla.org/sops/v3 1 github.com/syncthing/syncthing 1 twig/twig 1 eslint-detailed-reporter 1 moment-timezone 1 tqdm 1 org.jenkins-ci.plugins:quality-gates 1 github.com/authelia/authelia/v4 1 io.github.skylot:jadx-core 1 remove_dir_all 1 vantage6-server 1 org.jenkins-ci.plugins:hp-quality-center 1 loopback 1 org.cloudfoundry.identity:cloudfoundry-identity-server 1 uptime-kuma 1 bref/bref 1 mautic/core 1 org.jenkins-ci.plugins:dimensionsscm 1 marked 1 ruby_parser 1 ursa 1
Filter by Repository
https://github.com/tensorflow/tensorflow 109 https://github.com/concretecms/concretecms 18 https://github.com/moodle/moodle 17 https://github.com/shopware/platform 12 https://github.com/openstack/nova 11 https://github.com/octobercms/october 9 https://github.com/keycloak/keycloak 9 https://github.com/rails/rails 9 https://github.com/etcd-io/etcd 8 https://github.com/phpmyadmin/phpmyadmin 7 https://github.com/eclipse/jetty.project 7 https://github.com/umbraco/Umbraco-CMS 7 https://github.com/vyperlang/vyper 7 https://github.com/TYPO3/typo3 7 https://github.com/ethyca/fides 6 https://github.com/nodejs/undici 6 https://github.com/bytecodealliance/wasmtime 6 https://github.com/baserproject/basercms 5 https://github.com/jenkinsci/jenkins 5 https://github.com/kubernetes/kubernetes 5 https://github.com/xwiki/xwiki-platform 5 https://github.com/sweetalert2/sweetalert2 5 https://github.com/rack/rack 5 https://github.com/indutny/elliptic 5 https://github.com/puppetlabs/puppet 5 https://github.com/helm/helm 5 https://github.com/authzed/spicedb 5 https://github.com/shopware/shopware 4 https://github.com/silverstripe/silverstripe-framework 4 https://github.com/wintercms/winter 4 https://github.com/apache/tomcat 4 https://github.com/mattermost/mattermost 4 https://github.com/electron/electron 4 https://github.com/vantage6/vantage6 4 https://github.com/simplesamlphp/simplesamlphp 4 https://github.com/vaadin/platform 4 https://github.com/cilium/cilium 4 https://github.com/matrix-org/synapse 3 https://github.com/cosmos/cosmos-sdk 3 https://github.com/CVEProject/cvelist 3 https://github.com/openstack/keystone 3 https://github.com/wagtail/wagtail 3 https://github.com/apache/airflow 3 https://github.com/vaadin/flow 3 https://github.com/digitalbazaar/forge 3 https://gitlab.com/sequoia-pgp/sequoia 3 https://github.com/Graylog2/graylog2-server 3 https://github.com/Byron/gitoxide 3 https://github.com/opencontainers/runc 3 https://github.com/nautobot/nautobot 3 https://github.com/dpgaspar/Flask-AppBuilder 3 https://github.com/phusion/passenger 3 https://github.com/symfony/symfony 3 https://github.com/zenml-io/zenml 3 https://github.com/nervosnetwork/ckb 3 https://github.com/pyca/cryptography 3 https://github.com/ansible/ansible 3 https://github.com/openstack/glance 2 https://github.com/sigstore/cosign 2 https://github.com/octoprint/octoprint 2 https://github.com/openstack/horizon 2 https://github.com/hashicorp/nomad 2 https://github.com/apache/druid 2 https://github.com/cometbft/cometbft 2 https://github.com/mattermost/mattermost-plugin-jira 2 https://github.com/librenms/librenms 2 https://github.com/firefly-iii/firefly-iii 2 https://github.com/statamic/cms 2 https://github.com/ceph/ceph-deploy 2 https://github.com/schokokeksorg/freewvs 2 https://github.com/ntbosscher/gobase 2 https://github.com/gradio-app/gradio 2 https://github.com/opencontainers/distribution-spec 2 https://github.com/rust-lang/cargo 2 https://github.com/zopefoundation/Zope 2 https://github.com/aio-libs/aiohttp 2 https://github.com/Alexhuszagh/rust-lexical 2 https://github.com/apache/activemq 2 https://github.com/mutagen-io/mutagen 2 https://github.com/nextauthjs/next-auth 2 https://github.com/matrix-org/vodozemac 2 https://github.com/nats-io/nats-server 2 https://github.com/bcgit/bc-java 2 https://github.com/Flask-Middleware/flask-security 2 https://github.com/containerd/containerd 2 https://github.com/Sylius/Sylius 2 https://github.com/TYPO3/TYPO3.CMS 2 https://github.com/OpenZeppelin/openzeppelin-contracts 2 https://github.com/jenkinsci/ec2-plugin 2 https://github.com/parse-community/parse-server 2 https://github.com/micromatch/braces 2 https://github.com/craftcms/cms 2 https://github.com/quarkusio/quarkus 2 https://github.com/ezsystems/ezplatform-kernel 2 https://github.com/agnaistic/agnai 2 https://github.com/aws/s2n-quic 2 https://github.com/saltstack/salt 2 https://github.com/apollographql/apollo-server 2 https://github.com/moby/moby 2 https://github.com/theupdateframework/python-tuf 2 https://github.com/goharbor/harbor 2 https://github.com/answerdev/answer 2 https://github.com/RIAEvangelist/node-ipc 2 https://github.com/GilaCMS/gila 2 https://github.com/jetty/jetty.project 2 https://github.com/microweber/microweber 2 https://github.com/flarum/framework 2 https://github.com/yourls/yourls 1 https://github.com/spring-projects/spring-framework 1 https://github.com/langchain-ai/langchain 1 https://github.com/sigstore/sigstore-go 1 https://github.com/kiwitcms/Kiwi 1 https://github.com/topgrade-rs/topgrade 1 https://github.com/mportuga/eslint-detailed-reporter 1 https://github.com/moment/moment-timezone 1 https://github.com/jenkinsci/github-plugin 1 https://github.com/apache/maven-archetype 1 https://github.com/jenkinsci/parameterized-trigger-plugin 1 https://github.com/bbatsov/rubocop 1 https://github.com/syncthing/syncthing 1 https://github.com/petergoldstein/dalli 1 https://github.com/argoproj/argo-workflows 1 https://github.com/aws/aws-dynamodb-encryption-python 1 https://gitlab.com/gitlab-org/cves 1 https://github.com/pterodactyl/panel 1 https://github.com/auth0/lock 1 https://github.com/ipython/ipython 1 https://github.com/ckeditor/ckeditor4 1 https://github.com/artifacthub/hub 1 https://github.com/ConsenSys/discovery 1 https://github.com/waycrate/swhkd 1 https://github.com/alex/rply 1 https://github.com/encode/starlette 1 https://github.com/Icinga/ipl-web 1 https://github.com/cloudflare/tableflip 1 https://github.com/sjwall/mdx-mermaid 1 https://github.com/paragonie/random_compat 1 https://github.com/mautic/mautic 1 https://github.com/visionmedia/debug 1 https://github.com/node-js-libs/cli 1 https://github.com/octokit/octopoller.rb 1 https://github.com/tendermint/tendermint 1 https://github.com/jenkinsci/parameterized-remote-trigger-plugin 1 https://github.com/louislam/uptime-kuma 1 https://github.com/npm/npm-user-validate 1 https://github.com/jenkinsci/coverity-plugin 1 https://github.com/wiremock/wiremock 1 https://github.com/aedart/ion 1 https://github.com/kimai/kimai 1 https://github.com/actions/toolkit 1 https://github.com/SteeltoeOSS/security-advisories 1 https://github.com/aws/aws-encryption-sdk-cli 1 https://github.com/jenkinsci/gitlab-plugin 1 https://github.com/personnummer/python 1 https://github.com/jenkinsci/gitlab-branch-source-plugin 1 https://github.com/wasmerio/wasmer 1 https://github.com/risc0/risc0 1 https://github.com/jenkinsci/meliora-testlab-plugin 1 https://github.com/huandu/facebook 1 https://github.com/grpc/grpc-go 1 https://github.com/Qiskit/qiskit-ibm-runtime 1 https://github.com/slsa-framework/slsa-verifier 1 https://github.com/jenkinsci/resource-disposer-plugin 1 https://github.com/jenkinsci/support-core-plugin 1 https://github.com/DataDog/dd-trace-php 1 https://github.com/evmos/evmos 1 https://github.com/screetsec/VDD 1 https://github.com/xuxueli/xxl-job 1 https://github.com/tailscale/tailscale 1 https://github.com/visionmedia/send 1 https://github.com/alphagov/tech-docs-gem 1 https://github.com/DSpace/DSpace 1 https://github.com/Katello/katello 1 https://github.com/urllib3/urllib3 1 https://github.com/octokit/octokit.rb 1 https://github.com/isaacs/chownr 1 https://github.com/oauth2-proxy/oauth2-proxy 1 https://github.com/apache/lucene-solr 1 https://github.com/silverstripe/silverstripe-omnipay 1 https://github.com/MicrochipTech/cryptoauthlib 1 https://github.com/IncludeSecurity/safeurl-python 1 https://github.com/gayanhewa/sailsjs-cacheman 1 https://github.com/ethereum/web3.js 1 https://github.com/tektoncd/pipeline 1 https://github.com/DataDog/datadog-api-client-java 1 https://github.com/jenkinsci/ssh-agent-plugin 1 https://github.com/fluture-js/fluture-node 1 https://github.com/njmbb8/CVE-2024-42850 1 https://github.com/croogo/croogo 1 https://github.com/aws/s2n-tls 1 https://github.com/passbolt/passbolt_api 1 https://github.com/derbyjs/derby 1 https://github.com/puma/puma 1 https://github.com/rails/globalid 1 https://github.com/umbraco/Umbraco.Forms.Issues 1 https://github.com/python-pillow/Pillow 1 https://github.com/CosmWasm/wasmd 1 https://github.com/jenkinsci/qmetry-for-jira-test-management-plugin 1 https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID 1