Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture…
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1…
CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the l…
CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-s…
CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read …
CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1…
CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that c…
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e…
A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below, Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with n…
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The…
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be …
In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution…
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM t…
On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supporte…
In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in the vault. As per the “measured …
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea…
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the syst…
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privi…
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with Syst…
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with Syste…
In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privile…
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…
Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's…
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumenta…