Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2024-11-14 CVE-2022-31671 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs.
network
low complexity
linuxfoundation CWE-863
7.4
2024-10-10 CVE-2024-9798 Cleartext Storage of Sensitive Information vulnerability in Linuxfoundation Zowe API Mediation Layer
The health endpoint is public so everybody can see a list of all services.
network
low complexity
linuxfoundation CWE-312
5.3
2024-10-10 CVE-2024-9802 Cleartext Storage of Sensitive Information vulnerability in Linuxfoundation Zowe API Mediation Layer
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services.
network
low complexity
linuxfoundation CWE-312
5.3
2024-09-19 CVE-2023-27584 Use of Hard-coded Credentials vulnerability in Linuxfoundation Dragonfly
Dragonfly is an open source P2P-based file distribution and image acceleration system.
network
low complexity
linuxfoundation CWE-798
critical
9.8
2024-09-17 CVE-2024-45815 Unspecified vulnerability in Linuxfoundation Backstage
Backstage is an open framework for building developer portals.
network
low complexity
linuxfoundation
6.5
2024-09-17 CVE-2024-45816 Path Traversal vulnerability in Linuxfoundation Backstage
Backstage is an open framework for building developer portals.
network
low complexity
linuxfoundation CWE-22
6.5
2024-09-17 CVE-2024-46976 Cross-site Scripting vulnerability in Linuxfoundation Backstage
Backstage is an open framework for building developer portals.
network
low complexity
linuxfoundation CWE-79
5.4
2024-09-02 CVE-2024-20084 Out-of-bounds Read vulnerability in multiple products
In power, there is a possible out of bounds read due to a missing bounds check.
4.4
2024-09-02 CVE-2024-20085 Out-of-bounds Read vulnerability in multiple products
In power, there is a possible out of bounds read due to a missing bounds check.
4.4
2024-09-02 CVE-2024-20089 Improper Check for Unusual or Exceptional Conditions vulnerability in multiple products
In wlan, there is a possible denial of service due to incorrect error handling.
network
low complexity
linuxfoundation rdkcentral google CWE-754
7.5