Search CVE reports
41 – 50 of 42800 results
chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to...
1 affected package
golang-github-go-chi-chi
| Package | 24.04 LTS |
|---|---|
| golang-github-go-chi-chi | Needs evaluation |
(rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)
1 affected package
ruby-rails-html-sanitizer
| Package | 24.04 LTS |
|---|---|
| ruby-rails-html-sanitizer | Needs evaluation |
(js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2 ...)
1 affected package
node-js-yaml
| Package | 24.04 LTS |
|---|---|
| node-js-yaml | Needs evaluation |
Not in release
JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator...
1 affected package
jupyterlab
| Package | 24.04 LTS |
|---|---|
| jupyterlab | Not in release |
Not in release
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension...
1 affected package
jupyterlab
| Package | 24.04 LTS |
|---|---|
| jupyterlab | Not in release |
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted...
1 affected package
python-git
| Package | 24.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other...
1 affected package
python-git
| Package | 24.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing...
1 affected package
python-git
| Package | 24.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can...
1 affected package
python-git
| Package | 24.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method....
1 affected package
python-git
| Package | 24.04 LTS |
|---|---|
| python-git | Needs evaluation |