Search CVE reports
291 – 300 of 53321 results
Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker...
1 affected package
adminer
| Package | 22.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php...
1 affected package
adminer
| Package | 22.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute...
1 affected package
adminer
| Package | 22.04 LTS |
|---|---|
| adminer | Needs evaluation |
Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through...
1 affected package
hugo
| Package | 22.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in...
1 affected package
hugo
| Package | 22.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a...
1 affected package
hugo
| Package | 22.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id`...
1 affected package
hugo
| Package | 22.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the...
1 affected package
hugo
| Package | 22.04 LTS |
|---|---|
| hugo | Needs evaluation |
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field,...
1 affected package
python-git
| Package | 22.04 LTS |
|---|---|
| python-git | Needs evaluation |
Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once...
1 affected package
netty
| Package | 22.04 LTS |
|---|---|
| netty | Needs evaluation |