Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-26892 Use of Hard-coded Credentials vulnerability in multiple products
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
network
low complexity
linuxfoundation fedoraproject CWE-798
critical
9.8
2020-11-06 CVE-2020-26521 NULL Pointer Dereference vulnerability in multiple products
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
network
low complexity
linuxfoundation fedoraproject CWE-476
7.5
2020-10-16 CVE-2020-15157 Insufficiently Protected Credentials vulnerability in multiple products
In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability.
network
high complexity
linuxfoundation canonical debian CWE-522
6.1
2020-09-30 CVE-2020-26149 Insufficiently Protected Credentials vulnerability in Linuxfoundation Nats.Deno and Nats.Js
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
network
low complexity
linuxfoundation CWE-522
7.5
2020-09-30 CVE-2020-13794 Missing Authorization vulnerability in Linuxfoundation Harbor
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
network
low complexity
linuxfoundation CWE-862
4.3
2020-09-09 CVE-2020-15163 Insufficient Verification of Data Authenticity vulnerability in Linuxfoundation the Update Framework
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time.
network
high complexity
linuxfoundation CWE-345
8.2
2020-08-31 CVE-2020-15687 Unspecified vulnerability in Linuxfoundation Acrn 1.6.1/2.0
Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in the Service VM userspace, to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads.
network
low complexity
linuxfoundation
7.5
2020-07-15 CVE-2020-13788 Server-Side Request Forgery (SSRF) vulnerability in Linuxfoundation Harbor
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
network
low complexity
linuxfoundation CWE-918
4.3
2020-07-10 CVE-2020-11081 Unspecified vulnerability in Linuxfoundation Osquery
osquery before version 4.4.0 enables a privilege escalation vulnerability.
local
low complexity
linuxfoundation
8.2
2020-06-26 CVE-2020-10753 Injection vulnerability in multiple products
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway).
6.5