foreman-dynflow-sidekiq vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the foreman-dynflow-sidekiq package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Information Exposure

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
Arbitrary Command Injection

*
  • L
Resource Exhaustion

*
  • M
Key Exchange without Entity Authentication

*
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Reliance on Untrusted Inputs in a Security Decision

<0:2.1.2.19-1.el7sat
  • H
Directory Traversal

<0:2.1.2.19-1.el7sat
  • H
Incorrect Default Permissions

<0:2.1.2.19-1.el7sat
  • H
Improper Validation of Certificate with Host Mismatch

<0:2.1.2.19-1.el7sat
  • H
Improper Input Validation

<0:2.1.2.19-1.el7sat
  • H
HTTP Request Smuggling

<0:2.1.2.19-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:2.1.2.19-1.el7sat
  • H
Eval Injection

<0:2.1.2.19-1.el7sat
  • H
HTTP Response Splitting

<0:2.1.2.19-1.el7sat
  • H
Improper Authentication

<0:2.1.2.19-1.el7sat
  • H
Insufficiently Protected Credentials

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Improper Input Validation

<0:2.1.2.19-1.el7sat
  • H
Improperly Implemented Security Check for Standard

<0:2.1.2.19-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:2.1.2.19-1.el7sat
  • H
CVE-2018-3258

<0:2.1.2.19-1.el7sat
  • H
Missing Authorization

<0:2.1.2.19-1.el7sat
  • M
Information Exposure

*
  • H
OS Command Injection

*
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Missing Authorization

<0:2.3.1.20-1.el7sat
  • M
Information Exposure Through Log Files

<0:2.3.1.20-1.el7sat
  • H
Improper Input Validation

<0:2.1.2.19-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:2.1.2.19-1.el7sat
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • H
OS Command Injection

*
  • M
Cross-site Scripting (XSS)

*
  • H
Arbitrary Code Injection

*
  • M
Information Exposure

*
  • M
Incorrect Authorization

*
  • M
Improper Authorization

*
  • H
Insufficiently Protected Credentials

<0:2.1.2.19-1.el7sat
  • H
Improper Authentication

<0:2.1.2.19-1.el7sat
  • H
Information Exposure

<0:2.1.2.19-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • H
Incorrect Default Permissions

<0:2.1.2.19-1.el7sat
  • M
SQL Injection

<0:2.3.1.20-1.el7sat
  • H
Improperly Implemented Security Check for Standard

<0:2.1.2.19-1.el7sat
  • H
Missing Authorization

<0:2.1.2.19-1.el7sat
  • H
Improper Validation of Certificate with Host Mismatch

<0:2.1.2.19-1.el7sat
  • M
Execution with Unnecessary Privileges

<0:2.3.1.20-1.el7sat
  • H
HTTP Request Smuggling

<0:2.1.2.19-1.el7sat
  • M
Out-of-Bounds

<0:2.3.1.20-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:2.3.1.20-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:2.1.2.19-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:2.3.1.20-1.el7sat
  • H
Improper Input Validation

<0:2.1.2.19-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:2.3.1.20-1.el7sat
  • M
Improper Input Validation

<0:2.3.1.20-1.el7sat
  • M
Improper Input Validation

<0:2.3.1.20-1.el7sat
  • H
Eval Injection

<0:2.1.2.19-1.el7sat
  • H
Directory Traversal

<0:2.1.2.19-1.el7sat
  • H
HTTP Response Splitting

<0:2.1.2.19-1.el7sat
  • H
Reliance on Untrusted Inputs in a Security Decision

<0:2.1.2.19-1.el7sat
  • H
CVE-2018-3258

<0:2.1.2.19-1.el7sat
  • H
Covert Timing Channel

<0:2.1.2.19-1.el7sat
  • M
Covert Timing Channel

<0:2.3.1.20-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • M
Use After Free

<0:2.3.1.20-1.el7sat