Search CVE reports
1 – 10 of 45011 results
(rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)
1 affected package
ruby-rails-html-sanitizer
| Package | 20.04 LTS |
|---|---|
| ruby-rails-html-sanitizer | Needs evaluation |
(js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2 ...)
1 affected package
node-js-yaml
| Package | 20.04 LTS |
|---|---|
| node-js-yaml | Needs evaluation |
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method....
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an...
1 affected package
sblim-cmpi-base
| Package | 20.04 LTS |
|---|---|
| sblim-cmpi-base | Needs evaluation |