Security
Headlines
HeadlinesLatestCVEs

Source

ghsa

GHSA-r887-gfxh-m9rr: mrpack-install vulnerable to path traversal with dependency

### Impact Importing a malicious `.mrpack` file can cause path traversal while downloading files. This can lead to scripts or config files being placed or replaced at arbitrary locations, without the user noticing. ### Patches No patches yet. ### Workarounds Avoid importing `.mrpack` files from untrusted sources. ### References https://docs.modrinth.com/docs/modpacks/format_definition/#files

ghsa
#git
GHSA-65px-4cpf-697r: Cross-site scripting vulnerability found in answerdev/answer

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

GHSA-rmw8-7823-wp7f: Answer contains Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

GHSA-p7wj-c85f-xq9h: Answer has Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

GHSA-4cwh-8w4g-jxxh: Answer contains Improper Access Control vulnerability

Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

GHSA-hjmr-xm25-36mh: Answer subject to Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.

GHSA-qx34-47fc-vv79: Answer vulnerable to Race Condition

Race Condition in Switch in GitHub repository answerdev/answer prior to 1.0.4.

GHSA-74fp-r6jw-h4mp: Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON parsing

Unbounded recursion in JSON parsing allows malicious JSON input to cause excessive memory consumption or panics.

GHSA-2qxp-xmx6-cq4f: Cross-Site Request Forgery (CSRF) in wallabag/wallabag

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.

GHSA-3x2c-87cq-qx49: Cross-site Scripting (XSS) in wallabag/wallabag

Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.