Vulnerabilities > Linuxfoundation
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-08 | CVE-2023-25151 | Resource Exhaustion vulnerability in Linuxfoundation Opentelemetry-Go Contrib 0.38.0 opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. | 7.5 |
2023-01-26 | CVE-2022-25882 | Path Traversal vulnerability in Linuxfoundation Onnx Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd" | 7.5 |
2023-01-18 | CVE-2021-4314 | Improper Authentication vulnerability in Linuxfoundation Zowe API Mediation Layer 1.16/1.19 It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. | 5.3 |
2023-01-13 | CVE-2022-46463 | Missing Authentication for Critical Function vulnerability in Linuxfoundation Harbor An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. | 7.5 |
2023-01-04 | CVE-2022-4875 | Cross-site Scripting vulnerability in Linuxfoundation Fossology A vulnerability has been found in fossology and classified as problematic. | 6.1 |
2023-01-03 | CVE-2022-23506 | Information Exposure Through Log Files vulnerability in Linuxfoundation Spinnaker Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. | 7.5 |
2022-12-26 | CVE-2019-19030 | Unspecified vulnerability in Linuxfoundation Harbor Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists. | 5.3 |
2022-12-19 | CVE-2022-23536 | Unspecified vulnerability in Linuxfoundation Cortex 1.13.0/1.13.1/1.14.0 Cortex provides multi-tenant, long term storage for Prometheus. | 6.5 |
2022-12-07 | CVE-2022-23471 | Memory Leak vulnerability in Linuxfoundation Containerd containerd is an open source container runtime. | 6.5 |
2022-12-07 | CVE-2022-46770 | Infinite Loop vulnerability in Linuxfoundation Mirage Firewall qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255). | 7.5 |