Vulnerabilities > Linuxfoundation > High

DATE CVE VULNERABILITY TITLE RISK
2021-07-09 CVE-2021-36155 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Grpc Swift 1.0.0/1.1.0/1.1.1
LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.
network
low complexity
linuxfoundation CWE-770
7.5
2021-06-03 CVE-2021-32661 Unrestricted Upload of File with Dangerous Type vulnerability in Linuxfoundation @Backstage/Plugin-Techdocs
Backstage is an open platform for building developer portals.
network
low complexity
linuxfoundation CWE-434
7.3
2021-06-03 CVE-2021-32660 Unrestricted Upload of File with Dangerous Type vulnerability in Linuxfoundation @Backstage/Techdocs-Common
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs.
network
low complexity
linuxfoundation CWE-434
8.1
2021-05-27 CVE-2021-30465 Race Condition vulnerability in multiple products
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal.
network
high complexity
linuxfoundation fedoraproject CWE-362
8.5
2021-04-15 CVE-2021-20288 Improper Authentication vulnerability in multiple products
An authentication flaw was found in ceph in versions before 14.2.20.
7.2
2021-03-26 CVE-2021-20206 Path Traversal vulnerability in Linuxfoundation Container Network Interface
An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1.
network
low complexity
linuxfoundation CWE-22
7.2
2020-12-24 CVE-2020-11093 Unspecified vulnerability in Linuxfoundation Indy-Node
Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity.
network
low complexity
linuxfoundation
7.5
2020-12-11 CVE-2020-9301 Deserialization of Untrusted Data vulnerability in Linuxfoundation Spinnaker
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5.
network
low complexity
linuxfoundation CWE-502
8.8
2020-11-06 CVE-2020-26521 NULL Pointer Dereference vulnerability in multiple products
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
network
low complexity
linuxfoundation fedoraproject CWE-476
7.5
2020-09-30 CVE-2020-26149 Insufficiently Protected Credentials vulnerability in Linuxfoundation Nats.Deno and Nats.Js
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
network
low complexity
linuxfoundation CWE-522
7.5