Vulnerabilities > Linuxfoundation > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-14 CVE-2022-31668 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7
2024-11-14 CVE-2022-31669 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7
2024-11-14 CVE-2022-31670 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7
2024-11-14 CVE-2022-31671 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs.
network
low complexity
linuxfoundation CWE-863
7.4
2024-09-02 CVE-2024-20089 Improper Check for Unusual or Exceptional Conditions vulnerability in multiple products
In wlan, there is a possible denial of service due to incorrect error handling.
network
low complexity
linuxfoundation rdkcentral google CWE-754
7.5
2024-06-06 CVE-2024-5187 Unspecified vulnerability in Linuxfoundation Onnx 1.16.0
A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files.
network
low complexity
linuxfoundation
8.8
2024-01-31 CVE-2024-21626 Exposure of Resource to Wrong Sphere vulnerability in multiple products
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification.
local
low complexity
linuxfoundation fedoraproject CWE-668
8.6
2024-01-25 CVE-2024-23656 Inadequate Encryption Strength vulnerability in Linuxfoundation DEX 2.37.0
Dex is an identity service that uses OpenID Connect to drive authentication for other apps.
network
low complexity
linuxfoundation CWE-326
7.5
2024-01-19 CVE-2024-22424 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
high complexity
linuxfoundation argoproj CWE-352
8.3
2023-10-02 CVE-2023-32820 Reachable Assertion vulnerability in multiple products
In wlan firmware, there is a possible firmware assertion due to improper input handling.
network
low complexity
linuxfoundation mediatek google linux CWE-617
7.5