We’ve disclosed 3211 vulnerabilities
by Snyk Security
Researchers
How to fix?
Upgrade curl
to version 8.4.0 or higher.
electron <22.3.24 , >=24.0.0-alpha.1 <24.8.3 , >=25.0.0-alpha.1 <25.8.1 , >=26.0.0-alpha.1 <26.2.1
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.
Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity when the embeddedAsarIntegrityValidation
and onlyLoadAppFromAsar
fuses are enabled.
An attacker can edit files inside the .app
bundle on macOS, which these fuses are supposed to protect against, by gaining write access to the filesystem from which the app is launched.
Note
This is only exploitable if your app is launched from a filesystem the attacker has write access to and is specific to macOS, as these fuses are only supported on macOS.
fastapi-proxy-lib is a HTTP/WebSocket proxy for starlette/FastAPI.
Affected versions of this package are vulnerable to Information Exposure due to the shared usage of httpx.AsyncClient
in processing requests from different user clients. An attacker can exploit this to leak cookies among all user clients sharing the same httpx.AsyncClient
by sending a set-cookie
response header. This is only exploitable if the ForwardHttpProxy
is used, or if ReverseHttpProxy
or ReverseWebSocketProxy
are used for servers that may potentially send a set-cookie
response.
Affected versions of this package are vulnerable to SQL Injection via the /system/dept/edit
path. An attacker can manipulate SQL queries and gain unauthorized access to the database by injecting malicious SQL code. This is only exploitable if the application does not properly sanitize user input.
Insufficient Entropy in pubnub (pub)
Insufficient Entropy in pubnub (cocoapods)
Insufficient Entropy in github.com/pubnub/swift (swift)
Insufficient Entropy in com.pubnub:pubnub-kotlin (maven)
Insufficient Entropy in pubnub (cargo)
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.