
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Insertion of Sensitive Information Into Sent Data
Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data exposing process environment values, in getOptionsFromRootManifest.ts, which expands ${VAR} placeholders in the httpProxy, httpsProxy, and noProxy settings read from a repository-controlled manifest. An attacker can exfiltrate environment secrets such as NPM_TOKEN or GITHUB_TOKEN by publishing a repository whose pnpm-workspace.yaml sets a proxy URL that embeds ${VAR} in its hostname or userinfo, so the victim's pnpm install routes install traffic through the attacker proxy and leaks the expanded value. This requires the victim to run pnpm install in the untrusted repository with the relevant secrets present in the environment.
Deserialization of Untrusted Data
mlflow is a platform to streamline machine learning development, including tracking experiments, packaging code into reproducible runs, and sharing and deploying models.
Affected versions of this package are vulnerable to Deserialization of Untrusted Data in the _load_model() and _load_pyfunc() functions of the mlflow.statsmodels flavor (mlflow/statsmodels/__init__.py), which call statsmodels.iolib.api.load_pickle() without honoring the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control that guards the other flavors. An attacker can achieve arbitrary code execution by placing a malicious pickle file alongside an MLmodel artifact that declares the statsmodels flavor in an accessible artifact store, which executes when a victim calls mlflow.pyfunc.load_model() on it. This requires the attacker to write the artifact into a store the victim loads from, and the victim to load that specific model.
Out-of-bounds Read
Affected versions of this package are vulnerable to Out-of-bounds Read in the readAlignedVarUint function when out-of-band zero-copy deserialization is used. An attacker can access sensitive information or crash the application by providing specially crafted serialized data that triggers reads beyond the bounds of the underlying buffer.
Notes
-Versions after 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




