Vulnerabilities > Linuxfoundation > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-14 CVE-2022-31670 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7
2024-11-14 CVE-2022-31671 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs.
network
low complexity
linuxfoundation CWE-863
7.4
2024-09-02 CVE-2024-20089 Improper Check for Unusual or Exceptional Conditions vulnerability in multiple products
In wlan, there is a possible denial of service due to incorrect error handling.
network
low complexity
linuxfoundation rdkcentral google CWE-754
7.5
2024-06-06 CVE-2024-5187 Unspecified vulnerability in Linuxfoundation Onnx 1.16.0
A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files.
network
low complexity
linuxfoundation
8.8
2024-02-23 CVE-2024-27318 Path Traversal vulnerability in multiple products
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory.
network
low complexity
linuxfoundation fedoraproject CWE-22
7.5
2024-02-23 CVE-2024-26150 Path Traversal vulnerability in Linuxfoundation Backstage Backend-Common 0.21.0
`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals.
network
low complexity
linuxfoundation CWE-22
7.5
2024-01-31 CVE-2024-21626 Exposure of Resource to Wrong Sphere vulnerability in multiple products
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification.
local
low complexity
linuxfoundation fedoraproject CWE-668
8.6
2024-01-25 CVE-2024-23656 Inadequate Encryption Strength vulnerability in Linuxfoundation DEX 2.37.0
Dex is an identity service that uses OpenID Connect to drive authentication for other apps.
network
low complexity
linuxfoundation CWE-326
7.5
2024-01-19 CVE-2024-22424 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
high complexity
linuxfoundation argoproj CWE-352
8.3
2023-10-02 CVE-2023-32820 Reachable Assertion vulnerability in multiple products
In wlan firmware, there is a possible firmware assertion due to improper input handling.
network
low complexity
linuxfoundation mediatek google linux CWE-617
7.5