Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2022-01-04 CVE-2021-43832 Missing Authentication for Critical Function vulnerability in Linuxfoundation Spinnaker
Spinnaker is an open source, multi-cloud continuous delivery platform.
network
low complexity
linuxfoundation CWE-306
7.5
2022-01-04 CVE-2021-39143 Path Traversal vulnerability in Linuxfoundation Spinnaker
Spinnaker is an open source, multi-cloud continuous delivery platform.
local
low complexity
linuxfoundation CWE-22
3.6
2021-12-27 CVE-2021-45701 Use After Free vulnerability in Linuxfoundation Tremor-Script
An issue was discovered in the tremor-script crate before 0.11.6 for Rust.
network
low complexity
linuxfoundation CWE-416
7.5
2021-12-27 CVE-2021-45702 Use After Free vulnerability in Linuxfoundation Tremor-Script
An issue was discovered in the tremor-script crate before 0.11.6 for Rust.
network
low complexity
linuxfoundation CWE-416
5.0
2021-12-17 CVE-2021-23450 All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
network
low complexity
linuxfoundation oracle debian
critical
9.8
2021-12-17 CVE-2021-36779 Missing Authentication for Critical Function vulnerability in Linuxfoundation Longhorn
A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication.
low complexity
linuxfoundation CWE-306
critical
9.6
2021-12-17 CVE-2021-36780 Missing Authentication for Critical Function vulnerability in Linuxfoundation Longhorn
A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to.
low complexity
linuxfoundation CWE-306
8.1
2021-12-13 CVE-2021-41272 Incorrect Conversion between Numeric Types vulnerability in Linuxfoundation Besu 21.10.0/21.10.1
Besu is an Ethereum client written in Java.
network
low complexity
linuxfoundation CWE-681
5.0
2021-12-06 CVE-2021-43784 Integer Overflow or Wraparound vulnerability in multiple products
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification.
network
high complexity
linuxfoundation debian CWE-190
5.0
2021-11-26 CVE-2021-43776 Cross-site Scripting vulnerability in Linuxfoundation Auth Backend
Backstage is an open platform for building developer portals.
4.3