We’ve disclosed 2338 vulnerabilities
by Snyk Security
Researchers
How to fix?
Upgrade openssl
to version 3.0.7 or higher.
serve-lite is an a lightweight http-server for static file-based web development
Affected versions of this package are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url
passed as-is to path.join()
.
modoboa is a Mail hosting made simple
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) in the remove_permission()
function in views/identity.py
, accessible via the /admin
endpoint.
Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) as there are no validations that zip files being unpacked have entries that are not maliciously writing outside of the intended destination directory.
Directory Traversal in serve-lite (npm)
Cross-site Scripting (XSS) in serve-lite (npm)
Regular Expression Denial of Service (ReDoS) in ua-parser-js (npm)
Directory Traversal in onnx (pip)
Remote Code Execution (RCE) in com.bstek.uflo:uflo-core (maven)
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.