GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,053
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,582 advisories
Filter by severity
Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin
High
CVE-2023-24424
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
Jan 26, 2023
XML external entity vulnerability on agents in Jenkins MSTest Plugin
Critical
CVE-2023-24441
was published
for
org.jvnet.hudson.plugins:mstest
(Maven)
Jan 26, 2023
Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps Plugin
Moderate
CVE-2023-24439
was published
for
org.jenkins-ci.plugins:jira-steps
(Maven)
Jan 26, 2023
Exposure of system-scoped Kubernetes credentials in Jenkins Kubernetes Credentials Provider Plugin
Moderate
CVE-2023-24425
was published
for
com.cloudbees.jenkins.plugins:kubernetes-credentials-provider
(Maven)
Jan 26, 2023
Missing permission checks in Jenkins GitHub Pull Request Builder Plugin
Moderate
CVE-2023-24435
was published
for
org.jenkins-ci.plugins:ghprb
(Maven)
Jan 26, 2023
Missing permission check in Jenkins BearyChat Plugin
Moderate
CVE-2023-24459
was published
for
org.jenkins-ci.plugins:bearychat
(Maven)
Jan 26, 2023
CSRF vulnerability in Jenkins Keycloak Authentication Plugin
Moderate
CVE-2023-24457
was published
for
org.jenkins-ci.plugins:keycloak
(Maven)
Jan 26, 2023
Cross-site request forgery vulnerability in Jenkins BearyChat Plugin
High
CVE-2023-24458
was published
for
org.jenkins-ci.plugins:bearychat
(Maven)
Jan 26, 2023
symfont/process typosquatting malware spoofs symfony/process
High
GHSA-g3j5-mpp2-2fqm
was published
for
symfont/process
(Composer)
Jan 26, 2023
Security bug in ConvertToSinglePlane when used with untrusted content from the DDS loader
Moderate
GHSA-3w9w-9833-gcpv
was published
for
directxtex_desktop_2019
(NuGet)
Jan 26, 2023
magento-lts Reset Password not protected against well-timed CSRF
Moderate
CVE-2021-21395
was published
for
openmage/magento-lts
(Composer)
Jan 26, 2023
JWT audience claim is not verified
Critical
CVE-2023-22482
was published
for
github.com/argoproj/argo-cd
(Go)
Jan 25, 2023
Command injection in Git package in Wrangler
High
CVE-2022-31249
was published
for
github.com/rancher/wrangler
(Go)
Jan 25, 2023
Denial of service (DoS) when processing Git credentials
Moderate
CVE-2022-43756
was published
for
github.com/rancher/wrangler
(Go)
Jan 25, 2023
Controller reconciles apps outside configured namespaces when sharding is enabled
High
CVE-2023-22736
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Jan 25, 2023
Rancher generated tokens not revoked after modifications made to authentication provider
High
GHSA-c45c-39f6-6gw9
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects
High
CVE-2022-43757
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Command injection in Rancher Git package
Moderate
CVE-2022-43758
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster
High
CVE-2022-21953
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Privilege escalation in project role template binding (PRTB) and -promoted roles
High
CVE-2022-43759
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Rancher cattle-token is predictable
High
CVE-2022-43755
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Field-level security issue with .keyword fields in OpenSearch
Moderate
CVE-2023-23613
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Jan 24, 2023
Issue with whitespace in JWT roles in OpenSearch
Moderate
CVE-2023-23612
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Jan 24, 2023
Several quadratic complexity bugs may lead to denial of service in Commonmarker
Moderate
GHSA-636f-xm5j-pj9m
was published
for
commonmarker
(RubyGems)
Jan 24, 2023
ReDoS Vulnerability in ua-parser-js version
High
CVE-2022-25927
was published
for
ua-parser-js
(npm)
Jan 24, 2023
ProTip!
Advisories are also available from the
GraphQL API