Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2023-02-16 CVE-2023-25153 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Containerd
containerd is an open source container runtime.
local
low complexity
linuxfoundation CWE-770
5.5
2023-02-16 CVE-2023-25173 Incorrect Authorization vulnerability in Linuxfoundation Containerd
containerd is an open source container runtime.
local
low complexity
linuxfoundation CWE-863
7.8
2023-02-14 CVE-2023-25571 Cross-site Scripting vulnerability in Linuxfoundation products
Backstage is an open platform for building developer portals.
network
low complexity
linuxfoundation CWE-79
5.4
2023-02-08 CVE-2023-25163 Information Exposure Through Log Files vulnerability in Linuxfoundation Argo Continuous Delivery 2.6.0
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
low complexity
linuxfoundation CWE-532
6.5
2023-02-08 CVE-2023-25151 Resource Exhaustion vulnerability in Linuxfoundation Opentelemetry-Go Contrib 0.38.0
opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go.
network
low complexity
linuxfoundation CWE-400
7.5
2023-01-26 CVE-2023-22482 Incorrect Authorization vulnerability in Linuxfoundation Argo-Cd
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
low complexity
linuxfoundation CWE-863
8.8
2023-01-26 CVE-2023-22736 Missing Authorization vulnerability in Linuxfoundation Argo-Cd
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
high complexity
linuxfoundation CWE-862
8.5
2023-01-26 CVE-2022-25882 Path Traversal vulnerability in Linuxfoundation Onnx
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
network
low complexity
linuxfoundation CWE-22
7.5
2023-01-18 CVE-2021-4314 Improper Authentication vulnerability in Linuxfoundation Zowe API Mediation Layer
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user.
network
low complexity
linuxfoundation CWE-287
5.3
2023-01-13 CVE-2022-46463 Missing Authentication for Critical Function vulnerability in Linuxfoundation Harbor
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication.
network
low complexity
linuxfoundation CWE-306
7.5