Search CVE reports


Toggle filters

611 – 620 of 1538 results


CVE-2022-4123

Medium priority
Needs evaluation

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

1 affected package

golang-github-containers-buildah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-buildah Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2022-4122

Medium priority
Needs evaluation

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

1 affected package

golang-github-containers-buildah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-buildah Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2020-36565

Negligible priority
Needs evaluation

Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

1 affected package

golang-github-labstack-echo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-labstack-echo Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2022-24439

Medium priority

Some fixes available 6 of 12

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this...

2 affected packages

python-git, gitpython

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-git Needs evaluation Fixed Fixed Fixed
gitpython Not in release Not in release Not in release
Show less packages

CVE-2022-46146

Medium priority
Vulnerable

Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the...

2 affected packages

golang-github-prometheus-exporter-toolkit, prometheus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-prometheus-exporter-toolkit Not affected Vulnerable Not in release Not in release
prometheus Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-41912

Medium priority
Vulnerable

The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no...

1 affected package

golang-github-crewjam-saml

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-crewjam-saml Not affected Vulnerable Not in release Not in release
Show less packages

CVE-2022-3819

Medium priority
Ignored

An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-3818

Medium priority
Ignored

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-3793

Medium priority
Ignored

An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2022-3726

Medium priority
Ignored

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages