
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Malicious Package
etoro-auth is a malicious package. This package contains malicious code. Although this package may be attempting to impersonate a legitimate organization, it has no connection to that organization or its authors.
Insertion of Sensitive Information into Log File
snowflake-connector-python is a Snowflake Connector for Python
Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the logging process. An attacker can obtain authentication tokens, encryption keys, pre-signed URLs, and SAML assertions by accessing diagnostic logs that were insufficiently redacted. This is only exploitable if the attacker has read access to the log destination, such as the local filesystem, a log aggregation service, or a CI/CD artifact store.
Improper Certificate Validation
org.graalvm.sdk:graal-sdk is a high-performance JDK distribution designed to accelerate the execution of applications written in Java and other JVM languages along with support for JavaScript, Ruby, Python, and a number of other popular languages.
Affected versions of this package are vulnerable to Improper Certificate Validation in its TLS handshake handling of the no_certificate warning alert, which was honored regardless of the negotiated protocol version and silently removed the CERTIFICATE and CERTIFICATE_VERIFY handshake consumers when the server had client authentication requested. An attacker connecting as the TLS client can make the server drop its expectation of a client certificate and CertificateVerify by sending a no_certificate alert during a TLSv1.x handshake, even though that alert is defined only for SSLv3. This affects a JSSE server operating with client authentication requested rather than required, and the flaw carries high attack complexity.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




