We’ve disclosed3401vulnerabilities
by Snyk Security
Researchers
Upgrade postgresql
to version 13.19, 14.16, 15.11, 16.7, 17.3 or higher.
aws-cdk-lib is a Version 2 of the AWS Cloud Development Kit library
Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the DescribeCognitoUserPoolClient
CDK API. A user with access to the account where logs for this user pool are stored, and read permissions on the associated lambda function logs, can see the secrets generated by other users' cognito.UserPoolClient
constructs.
Note: After upgrading, applications must be redeployed with the feature flag @aws-cdk/cognito:logUserPoolClientSecretValue
set to false to remediate this vulnerability.
dbgpt is a DB-GPT is an experimental open-source project that uses localized GPT large models to interact with your data and environment. With this solution, you can beassured that there is no risk of data leakage, and your data is 100% private and secure.
Affected versions of this package are vulnerable to SQL Injection via the web API POST /api/v1/editor/chart/run
.
Affected versions of this package are vulnerable to Deserialization of Untrusted Data in the session handling logic in SessionStoreImpl#get
. An attacker can execute code by sending a malicious payload beginning with "b64~", which is deserialized unsafely.
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.