Search CVE reports
961 – 970 of 50075 results
grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type...
1 affected package
golang-github-grpc-ecosystem-grpc-gateway
| Package | 22.04 LTS |
|---|---|
| golang-github-grpc-ecosystem-grpc-gateway | Needs evaluation |
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line...
1 affected package
node-morgan
| Package | 22.04 LTS |
|---|---|
| node-morgan | Needs evaluation |
Not in release
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because...
1 affected package
rust-gix-transport
| Package | 22.04 LTS |
|---|---|
| rust-gix-transport | Not in release |
Not in release
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to...
1 affected package
rust-gix-pack
| Package | 22.04 LTS |
|---|---|
| rust-gix-pack | Not in release |
Not in release
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via...
2 affected packages
rust-gix, rust-gix-validate
| Package | 22.04 LTS |
|---|---|
| rust-gix | Not in release |
| rust-gix-validate | Not in release |
Not in release
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked...
1 affected package
rust-gix
| Package | 22.04 LTS |
|---|---|
| rust-gix | Not in release |
Not in release
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to...
1 affected package
rust-gix
| Package | 22.04 LTS |
|---|---|
| rust-gix | Not in release |
Not in release
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band...
1 affected package
rust-gix-packetline
| Package | 22.04 LTS |
|---|---|
| rust-gix-packetline | Not in release |
Not in release
gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and...
1 affected package
rust-gix-credentials
| Package | 22.04 LTS |
|---|---|
| rust-gix-credentials | Not in release |
Not in release
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization...
4 affected packages
rust-gix, rust-gix-features, rust-gix-worktree, rust-gix-worktree-state
| Package | 22.04 LTS |
|---|---|
| rust-gix | Not in release |
| rust-gix-features | Not in release |
| rust-gix-worktree | Not in release |
| rust-gix-worktree-state | Not in release |