Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Improper Control of Dynamically-Managed Code Resources
@nocobase/plugin-workflow-javascript is an Execute a piece of JavaScript in an isolated Node.js environment.
Affected versions of this package are vulnerable to Improper Control of Dynamically-Managed Code Resources via the console object passed into the sandbox context, which exposes host-realm stream objects such as console._stdout and console._stderr. An attacker can execute arbitrary code with root privileges by traversing the prototype chain to escape the sandbox and gain access to the host environment.
Command Injection
Affected versions of this package are vulnerable to Command Injection when serving models with enable_mlserver=True due to unsanitized input being embedded into a shell command. An attacker can execute arbitrary commands by supplying specially crafted model URIs containing shell metacharacters.
Excessive Platform Resource Consumption within a Loop
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.
Affected versions of this package are vulnerable to Excessive Platform Resource Consumption within a Loop via the scope parameter processing in the OpenID Connect (OIDC) token endpoint. An attacker can exhaust server resources and cause prolonged response times by sending a specially crafted POST request with an excessively long scope value.
Recent vulnerabilities disclosed by Snyk
- M
Division by zero in jsrsasign (npm)- H
Incorrect Conversion between Numeric Types in jsrsasign (npm)- C
Missing Cryptographic Step in jsrsasign (npm)- C
Improper Verification of Cryptographic Signature in jsrsasign (npm)- C
Incomplete Comparison with Missing Factors in jsrsasign (npm)
Snyk security
researchers
have disclosed
3482
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.