We’ve disclosed3416vulnerabilities
by Snyk Security
Researchers
Upgrade postgresql
to version 13.19, 14.16, 15.11, 16.7, 17.3 or higher.
blipkitgit is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
h11 is an A pure-Python, bring-your-own-I/O implementation of HTTP/1.1
Affected versions of this package are vulnerable to HTTP Request Smuggling via the class ChunkedReader
in _readers.py
file, which performs the parsing of line terminators in chunked-coding message bodies. An attacker can exploit this to bypass security controls and smuggle HTTP requests by crafting malformed chunked-encoding bodies.
Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the function saveConfigFile
in the file HealthUtils.java
, where a failed configuration file write triggers. An attacker can gain unauthorized access to system credentials by accessing the exposed logs.
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.