We’ve disclosed3416vulnerabilities
by Snyk Security
Researchers
Upgrade postgresql
to version 13.19, 14.16, 15.11, 16.7, 17.3 or higher.
@gluestack-ui/utils is an Utility functions used internally in gluestack-ui
Affected versions of this package are vulnerable to Embedded Malicious Code that conceals a remote access trojan (RAT). A malicious actor compromised a public access token associated with one of Gluestack-UI’s contributors; This allowed the attacker to publish tampered versions of react-native-aria packages along with a @gluestack-ui/utils package to npm.
Affected versions of this package are vulnerable to SQL Injection through multiple vector store integrations. An attacker can read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the library in a web application.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) through the report serving functionality. An attacker capable of changing report content can bypass the Content-Security-Policy introduced in Jenkins 1.641 and 1.625.3.
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.