We’ve disclosed3414vulnerabilities
by Snyk Security
Researchers
Upgrade postgresql
to version 13.19, 14.16, 15.11, 16.7, 17.3 or higher.
@cloudflare/workers-oauth-provider is an OAuth provider for Cloudflare Workers
Affected versions of this package are vulnerable to Open Redirect due to the missing validation of the redirect URI on the authorize endpoint. An attacker can impersonate a user and potentially steal credentials by tricking a victim into visiting a malicious website. This is only exploitable if the OAuth server's authorized callback is designed to auto-approve authorizations that appear to come from an OAuth client that the victim has previously authorized.
llama-index-readers-web is a llama-index readers web integration
Affected versions of this package are vulnerable to Uncontrolled Recursion due to improper handling of the max_depth
parameter in the get_article_urls
function. An attacker can exhaust system resources and crash the application through repeated function calls, ultimately exceeding Python's recursion limit.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the MyAccountPortlet
fields such as First Name, Middle Name, and Last Name. A user can inject malicious scripts that persist within the database and are executed when other users view these modified fields through the search feature.
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.