The Wayback Machine - https://web.archive.org/web/20210607065642/https://github.com/advisories
Skip to content

GitHub Advisory Database

XML Entity Expansion
CVE-2017-18640 (High severity) was published Jun 4, 2021 org.yaml:snakeyaml (Maven)
Reflected XSS when using flashMessages or languageDictionary
CVE-2021-32641 (High severity) was published Jun 4, 2021 auth0-lock (npm)
Generation of Error Message Containing Sensitive Information in RESTEasy client
CVE-2020-25633 (Moderate severity) was published Jun 3, 2021 org.jboss.resteasy:resteasy-client (Maven)
Script injection
CVE-2021-32660 (Moderate severity) was published Jun 4, 2021 @backstage/techdocs-common (npm)
Script injection
CVE-2021-32661 (Moderate severity) was published Jun 4, 2021 @backstage/plugin-techdocs (npm)
Path traversal
CVE-2021-32662 (Moderate severity) was published Jun 4, 2021 @backstage/techdocs-common (npm)
Inadequate Encryption Strength
CVE-2017-1000486 (Critical severity) was published Jun 3, 2021 org.primefaces:primefaces (Maven)
Improper rate limiting in Koel
CVE-2021-33563 (High severity) was published Jun 1, 2021 phanan/koel (Composer)
Insertion of Sensitive Information into Log File in ansible
CVE-2021-20191 (Moderate severity) was published Jun 1, 2021 ansible (pip)
Insertion of Sensitive Information into Log File in ansible
CVE-2021-20178 (Moderate severity) was published Jun 1, 2021 ansible (pip)
Improper Verification of Cryptographic Signature in Apache Pulsar
CVE-2021-22160 (Critical severity) was published Jun 1, 2021 org.apache.pulsar:pulsar (Maven)
Vulnerability in hyperkitty
CVE-2021-33038 (High severity) was published Jun 1, 2021 HyperKitty (pip)
Improper Verification of Cryptographic Signature in aws-encryption-sdk-java
GHSA-55xh-53m6-936r (Moderate severity) was published Jun 1, 2021 com.amazonaws:aws-encryption-sdk-java (Maven)
Improper Verification of Cryptographic Signature in aws-encryption-sdk
GHSA-x5h4-9gqw-942j (Moderate severity) was published Jun 1, 2021 aws-encryption-sdk (pip)
Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript
GHSA-h45p-w933-jxh3 (Moderate severity) was published Jun 1, 2021 @aws-crypto/client-browser (npm)
Improper Verification of Cryptographic Signature in aws-encryption-sdk-cli
GHSA-89v2-g37m-g3ff (Moderate severity) was published Jun 1, 2021 aws-encryption-sdk-cli (pip)
Authentication Bypass in Kiali
CVE-2021-20278 (Moderate severity) was published Jun 1, 2021 github.com/kiali/kiali (Go)
Remote code execution in Dragonfly
CVE-2021-33564 (Critical severity) was published Jun 2, 2021 dragonfly (RubyGems)
Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
CVE-2021-33503 (Moderate severity) was published Jun 1, 2021 urllib3 (pip)
NariyoshiChida
Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
GHSA-jq42-hfch-42f3 (Moderate severity) was published Jun 1, 2021 github.com/hpcng/singularity (Go)
Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
CVE-2021-32635 (Moderate severity) was published Jun 1, 2021 github.com/sylabs/singularity (Go)
EmmEff
ReDoS in Sec-Websocket-Protocol header
CVE-2021-32640 (Moderate severity) was published May 28, 2021 ws (npm)
robmcl4
constructEvent does not verify header
GHSA-4g53-vp7q-gfjv (High severity) was published May 28, 2021 @worker-tools/stripe-webhook (npm)
Cross-site scripting vulnerability in TinyMCE
GHSA-5vm8-hhgr-jcjp (Moderate severity) was published May 28, 2021 tinymce (npm)
StaticFile.fromUrl can leak presence of a directory
CVE-2021-32643 (Moderate severity) was published May 28, 2021 org.http4s:http4s-core (Maven)
ProTip! Advisories are also available from the GraphQL API