We’ve disclosed3416vulnerabilities
by Snyk Security
Researchers
Upgrade postgresql
to version 13.19, 14.16, 15.11, 16.7, 17.3 or higher.
@misskey-dev/summaly is a Get web page's summary
Affected versions of this package are vulnerable to Origin Validation Error in got.scpaping
. An attacker can probe a victim's internal network for HTTP services that aren't supposed to be exposed to the outside world by using an HTTP redirect to bypass IP filtering. This is only exploitable if the attacker can manipulate the HTTP HEAD
and GET
requests to redirect to a private IP address.
salt is a new approach to infrastructure management built on a dynamic communication bus. Salt can be used for data-driven orchestration, remote execution for any infrastructure, configuration management for any app stack, and much more.
Affected versions of this package are vulnerable to Arbitrary Command Injection via the on demand
pillar process when a specially crafted git URL is provided. An attacker can execute arbitrary commands on the master with the same privileges as the master process by exploiting access to a minion key.
org.webjars.npm:serve-handler is a package responsible for routing requests and handling responses.
Affected versions of this package are vulnerable to Information Exposure. The unlisted
property removes the file/folder from directory list but still allows viewing them by visiting their path.
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.