We’ve disclosed3445vulnerabilities
by Snyk Security
Researchers
Avoid using all malicious instances of the ngx-bootstrap package.
parse-server is a version of the Parse backend that can be deployed to any infrastructure that can run Node.js.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the file upload functionality. An attacker can cause the server to crash by supplying a crafted URI parameter that triggers a request to an arbitrary URI, resulting in a denial of service.
langgraph-checkpoint is a library with base interfaces for LangGraph checkpoint savers.
Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the JsonPlusSerializer deserialization process of payloads saved in the json serialization mode. An attacker can execute arbitrary code by supplying a maliciously crafted payload that is deserialized in the json mode, which supports constructor-style formats for custom objects.
org.apache.synapse:synapse-extensions is an Apache Synapse - Extensions
Affected versions of this package are vulnerable to Arbitrary Code Injection due to a lack of controls on the GraalJS and NashornJS Script Mediator engines. An attacker can execute arbitrary code with elevated privileges by submitting crafted scripts to the integration runtime environment. This is only exploitable if the attacker is an authenticated user with administrator or API creator privileges, depending on the product configuration.
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.