Search CVE reports
891 – 900 of 34564 results
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing...
1 affected package
python-git
| Package | 26.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can...
1 affected package
python-git
| Package | 26.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method....
1 affected package
python-git
| Package | 26.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with...
1 affected package
python-git
| Package | 26.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files...
1 affected package
python-git
| Package | 26.04 LTS |
|---|---|
| python-git | Needs evaluation |
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an...
1 affected package
sblim-cmpi-base
| Package | 26.04 LTS |
|---|---|
| sblim-cmpi-base | Needs evaluation |
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link,...
1 affected package
sblim-sfcb
| Package | 26.04 LTS |
|---|---|
| sblim-sfcb | Needs evaluation |
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially...
1 affected package
sblim-sfcb
| Package | 26.04 LTS |
|---|---|
| sblim-sfcb | Needs evaluation |
(fast-xml-parser allows users to process XML from JS object without C/C ...)
1 affected package
node-webfont
| Package | 26.04 LTS |
|---|---|
| node-webfont | Needs evaluation |
(node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...)
1 affected package
node-tar
| Package | 26.04 LTS |
|---|---|
| node-tar | Needs evaluation |