Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-37300High· 8.1Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
GHSA-7jmw-8259-q9jxMediumTraefik has unexpected behavior with IPv4-mapped IPv6 addresses
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses
CVE-2024-37301High· 7.2document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
CVE-2024-35255Medium· 5.5Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
GHSA-87m9-rv8p-rgmgHigh· 7.5go-grpc-compression has a zstd decompression bombing vulnerability
go-grpc-compression has a zstd decompression bombing vulnerability
CVE-2021-41089Low· 2.8`docker cp` allows unexpected chmod of host files in Moby Docker Engine
`docker cp` allows unexpected chmod of host files in Moby Docker Engine
CVE-2021-41092Medium· 5.4Docker CLI leaks private registry credentials to registry-1.docker.io
Docker CLI leaks private registry credentials to registry-1.docker.io
CVE-2024-4680Low· 3.9zenml-io/zenml does not expire the session after password reset
zenml-io/zenml does not expire the session after password reset
CVE-2024-37388Critical· 9.1ebookmeta XML External Entity vulnerability
ebookmeta XML External Entity vulnerability
CVE-2024-37152Medium· 5.3PoCUnauthenticated Access to sensitive settings in Argo CD
Unauthenticated Access to sensitive settings in Argo CD
CVE-2024-36106Medium· 4.3Argo-cd authenticated users can enumerate clusters by name
Argo-cd authenticated users can enumerate clusters by name
GHSA-w235-7p84-xx57Medium· 6.5Tornado has a CRLF injection in CurlAsyncHTTPClient headers
Tornado has a CRLF injection in CurlAsyncHTTPClient headers
CVE-2024-5206Medium· 5.3scikit-learn sensitive data leakage vulnerability
scikit-learn sensitive data leakage vulnerability
CVE-2024-35178High· 7.5Jupyter server on Windows discloses Windows user password hash
Jupyter server on Windows discloses Windows user password hash
CVE-2024-5452Critical· 9.8PoCRemote code execution in pytorch lightning
Remote code execution in pytorch lightning
GHSA-753j-mpmx-qq6gMedium· 5.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado
CVE-2024-2965Medium· 4.2Denial of service in langchain-community
Denial of service in langchain-community
CVE-2024-5550Medium· 5.3Arbitrary system path lookup in h20
Arbitrary system path lookup in h20
CVE-2024-3095Medium· 4.8Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
CVE-2024-5225Medium· 6.4SQL injection in litellm
SQL injection in litellm
CVE-2024-4325High· 8.6PoCServer-Side Request Forgery in gradio
Server-Side Request Forgery in gradio
CVE-2024-4890Medium· 4.9PoCSQL injection in litellm
SQL injection in litellm
CVE-2024-3099Medium· 5.4Undefined Behavior in mlflow
Undefined Behavior in mlflow
CVE-2024-4888Medium· 6.5Arbitrary file deletion in litellm
Arbitrary file deletion in litellm
CVE-2024-3429Critical· 9.8LoLLMS Path Traversal vulnerability
LoLLMS Path Traversal vulnerability
GO-2024-2880NoneTraefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
GO-2024-2726NoneTraefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
CVE-2024-5629Medium· 4.7PyMongo Out-of-bounds Read in the bson module
PyMongo Out-of-bounds Read in the bson module
CVE-2024-4253Critical· 9.1PoCA command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…
CVE-2024-5154High· 8.1malicious container creates symlink "mtab" on the host External
malicious container creates symlink "mtab" on the host External