CVE-2024-3657 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 10 months ago 389-ds-base: potential denial of service via specially crafted kerberos as-req request A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service Affected products 389-ds:1.4 * 389-ds-base * redhat-ds:11 * redhat-ds:12 * 389-ds:1.4/389-ds-base redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base Matching in nixpkgs pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable 3.1.1 nixos-unstable-small 3.1.1 nixpkgs-unstable 3.1.1 Package maintainers: 1 @ners ners <ners@gmx.ch>
pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable 3.1.1 nixos-unstable-small 3.1.1 nixpkgs-unstable 3.1.1
CVE-2024-5953 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 10 months ago 389-ds-base: malformed userpassword hash may cause denial of service A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password. Affected products 389-ds:1.4 * 389-ds-base * redhat-ds:11 * redhat-ds:12 * 389-ds:1.4/389-ds-base redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base Matching in nixpkgs pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable 3.1.1 nixos-unstable-small 3.1.1 nixpkgs-unstable 3.1.1 Package maintainers: 1 @ners ners <ners@gmx.ch>
pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable 3.1.1 nixos-unstable-small 3.1.1 nixpkgs-unstable 3.1.1
CVE-2025-26778 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 10 months ago WordPress Gallery Custom Links Plugin <= 2.2.1 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Gallery allows Stored XSS. This issue affects Gallery: from n/a through 2.2.1. Affected products gallery =<2.2.1 Matching in nixpkgs pkgs.fgallery Static photo gallery generator nixos-unstable 1.9.1 nixos-unstable-small 1.9.1 nixpkgs-unstable 1.9.1 pkgs.gallery-dl Command-line program to download image-galleries and -collections from several image hosting sites nixos-unstable 1.27.7 nixos-unstable-small 1.27.7 nixpkgs-unstable 1.27.7 pkgs.lomiri.lomiri-gallery-app Photo gallery application for Ubuntu Touch devices nixos-unstable 3.1.0 nixos-unstable-small 3.1.0 nixpkgs-unstable 3.1.0 pkgs.libsForQt5.kirigami-gallery View examples of Kirigami components nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5 pkgs.kdePackages.kirigami-gallery Kirigami component gallery application nixos-unstable 24.08.3 nixos-unstable-small 24.08.3 nixpkgs-unstable 24.08.3 pkgs.plasma5Packages.kirigami-gallery View examples of Kirigami components nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5 pkgs.azure-cli-extensions.image-gallery Support for Azure Image Gallery nixos-unstable 0.1.3 nixos-unstable-small 0.1.3 nixpkgs-unstable 0.1.3 pkgs.lomiri.lomiri-gallery-app.x86_64-linux Photo gallery application for Ubuntu Touch devices nixos-unstable ??? nixos-unstable-small 3.1.0 pkgs.lomiri.lomiri-gallery-app.aarch64-linux Photo gallery application for Ubuntu Touch devices nixos-unstable ??? nixos-unstable-small 3.1.0 pkgs.libsForQt5.kirigami-gallery.x86_64-linux View examples of Kirigami components nixos-unstable ??? nixos-unstable-small 23.08.5 pkgs.libsForQt5.kirigami-gallery.aarch64-linux View examples of Kirigami components nixos-unstable ??? nixos-unstable-small 23.08.5 pkgs.azure-cli-extensions.gallery-service-artifact Microsoft Azure Command-Line Tools GalleryServiceArtifact Extension nixos-unstable 1.0.0b1 nixos-unstable-small 1.0.0b1 nixpkgs-unstable 1.0.0b1 pkgs.plasma5Packages.kirigami-gallery.x86_64-linux View examples of Kirigami components nixos-unstable ??? nixpkgs-unstable 23.08.5 pkgs.plasma5Packages.kirigami-gallery.aarch64-linux View examples of Kirigami components nixos-unstable ??? nixpkgs-unstable 23.08.5 Package maintainers: 13 @ShadowRZ 夜坂雅 <shadowrz+nixpkgs@disroot.org> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @NickCao Nick Cao <nickcao@nichi.co> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @mjm Matt Moriarity <matt@mattmoriarity.com> @K900 Ilya K. <me@0upti.me> @katexochen Paul Meyer <katexochen0@gmail.com> @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @dawidsowa Dawid Sowa <dawid_sowa@posteo.net> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @OPNA2608 Cosima Neidahl <opna2608@protonmail.com>
pkgs.fgallery Static photo gallery generator nixos-unstable 1.9.1 nixos-unstable-small 1.9.1 nixpkgs-unstable 1.9.1
pkgs.gallery-dl Command-line program to download image-galleries and -collections from several image hosting sites nixos-unstable 1.27.7 nixos-unstable-small 1.27.7 nixpkgs-unstable 1.27.7
pkgs.lomiri.lomiri-gallery-app Photo gallery application for Ubuntu Touch devices nixos-unstable 3.1.0 nixos-unstable-small 3.1.0 nixpkgs-unstable 3.1.0
pkgs.libsForQt5.kirigami-gallery View examples of Kirigami components nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5
pkgs.kdePackages.kirigami-gallery Kirigami component gallery application nixos-unstable 24.08.3 nixos-unstable-small 24.08.3 nixpkgs-unstable 24.08.3
pkgs.plasma5Packages.kirigami-gallery View examples of Kirigami components nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5
pkgs.azure-cli-extensions.image-gallery Support for Azure Image Gallery nixos-unstable 0.1.3 nixos-unstable-small 0.1.3 nixpkgs-unstable 0.1.3
pkgs.lomiri.lomiri-gallery-app.x86_64-linux Photo gallery application for Ubuntu Touch devices nixos-unstable ??? nixos-unstable-small 3.1.0
pkgs.lomiri.lomiri-gallery-app.aarch64-linux Photo gallery application for Ubuntu Touch devices nixos-unstable ??? nixos-unstable-small 3.1.0
pkgs.libsForQt5.kirigami-gallery.x86_64-linux View examples of Kirigami components nixos-unstable ??? nixos-unstable-small 23.08.5
pkgs.libsForQt5.kirigami-gallery.aarch64-linux View examples of Kirigami components nixos-unstable ??? nixos-unstable-small 23.08.5
pkgs.azure-cli-extensions.gallery-service-artifact Microsoft Azure Command-Line Tools GalleryServiceArtifact Extension nixos-unstable 1.0.0b1 nixos-unstable-small 1.0.0b1 nixpkgs-unstable 1.0.0b1
pkgs.plasma5Packages.kirigami-gallery.x86_64-linux View examples of Kirigami components nixos-unstable ??? nixpkgs-unstable 23.08.5
pkgs.plasma5Packages.kirigami-gallery.aarch64-linux View examples of Kirigami components nixos-unstable ??? nixpkgs-unstable 23.08.5
CVE-2023-6918 3.7 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 10 months ago Libssh: missing checks for return values for digests A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection. Affected products libssh * libssh2 mingw-libssh2 Matching in nixpkgs pkgs.libssh SSH client library nixos-unstable 0.11.1 nixos-unstable-small 0.11.1 nixpkgs-unstable 0.11.1 pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-unstable 1.11.1 nixos-unstable-small 1.11.1 nixpkgs-unstable 1.11.1 pkgs.libssh.x86_64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.aarch64-linux SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh.x86_64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.x86_64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh.aarch64-darwin SSH client library nixos-unstable ??? nixos-unstable-small 0.11.1 pkgs.libssh2.aarch64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.libssh2.x86_64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh libssh bindings nixos-unstable 0.1.0.0 nixos-unstable-small 0.1.0.0 nixpkgs-unstable 0.1.0.0 pkgs.libssh2.aarch64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1 pkgs.haskellPackages.libssh2 FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable 0.2.0.9 nixos-unstable-small 0.2.0.9 nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 pkgs.python311Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2 pkgs.haskellPackages.libssh.x86_64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.aarch64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh.x86_64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.x86_64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh.aarch64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.haskellPackages.libssh2.aarch64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.x86_64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2.aarch64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9 pkgs.haskellPackages.libssh2-conduit.x86_64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.x86_64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.haskellPackages.libssh2-conduit.aarch64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1 pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-unstable libssh2 nixos-unstable-small libssh2 nixpkgs-unstable libssh2 Package maintainers: 3 @svanderburg Sander van der Burg <s.vanderburg@tudelft.nl> @geluk Johan Geluk <johan+nix@geluk.io> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
pkgs.libssh SSH client library nixos-unstable 0.11.1 nixos-unstable-small 0.11.1 nixpkgs-unstable 0.11.1
pkgs.libssh2 Client-side C library implementing the SSH2 protocol nixos-unstable 1.11.1 nixos-unstable-small 1.11.1 nixpkgs-unstable 1.11.1
pkgs.libssh2.x86_64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.libssh2.aarch64-linux Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.libssh2.x86_64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.haskellPackages.libssh libssh bindings nixos-unstable 0.1.0.0 nixos-unstable-small 0.1.0.0 nixpkgs-unstable 0.1.0.0
pkgs.libssh2.aarch64-darwin Client-side C library implementing the SSH2 protocol nixos-unstable ??? nixos-unstable-small 1.11.1
pkgs.haskellPackages.libssh2 FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable 0.2.0.9 nixos-unstable-small 0.2.0.9 nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2-conduit Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1
pkgs.python311Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2
pkgs.python312Packages.ansible-pylibssh Python bindings to client functionality of libssh specific to Ansible use case nixos-unstable 1.2.2 nixos-unstable-small 1.2.2 nixpkgs-unstable 1.2.2
pkgs.haskellPackages.libssh.aarch64-linux libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh.x86_64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh2.x86_64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh.aarch64-darwin libssh bindings nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.haskellPackages.libssh2.aarch64-linux FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2.x86_64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2.aarch64-darwin FFI bindings to libssh2 SSH2 client library (http://libssh2.org/) nixos-unstable ??? nixpkgs-unstable 0.2.0.9
pkgs.haskellPackages.libssh2-conduit.x86_64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.aarch64-linux Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.x86_64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.haskellPackages.libssh2-conduit.aarch64-darwin Conduit wrappers for libssh2 FFI bindings (see libssh2 package) nixos-unstable ??? nixpkgs-unstable 0.2.1
pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2 Test whether libssh2-1.11.1 exposes pkg-config modules libssh2 nixos-unstable libssh2 nixos-unstable-small libssh2 nixpkgs-unstable libssh2
CVE-2023-49920 created 10 months ago Apache Airflow: Missing CSRF protection on DAG/trigger Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent. Users are advised to upgrade to version 2.8.0 or later which is not affected Affected products apache-airflow <2.8.0 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2023-4256 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 10 months ago Tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack. Affected products tcpreplay Matching in nixpkgs pkgs.tcpreplay Suite of utilities for editing and replaying network traffic nixos-unstable 4.5.1 nixos-unstable-small 4.5.1 nixpkgs-unstable 4.5.1 Package maintainers: 1 @proteansec Dejan Lukan <dejan@proteansec.com>
pkgs.tcpreplay Suite of utilities for editing and replaying network traffic nixos-unstable 4.5.1 nixos-unstable-small 4.5.1 nixpkgs-unstable 4.5.1
CVE-2024-29735 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): NONE created 10 months ago Apache Airflow: Potentially harmful permission changing by log task handler Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set permissions for all parent folders of log folder, in default configuration adding write access to Unix group of the folders. In the case Airflow is run with the root user (not recommended) it added group write permission to all folders up to the root of the filesystem. If your log files are stored in the home directory, these permission changes might impact your ability to run SSH operations after your home directory becomes group-writeable. This issue does not affect users who use or extend Airflow using Official Airflow Docker reference images ( https://hub.docker.com/r/apache/airflow/ ) - those images require to have group write permission set anyway. You are affected only if you install Airflow using local installation / virtualenv or other Docker images, but the issue has no impact if docker containers are used as intended, i.e. where Airflow components do not share containers with other applications and users. Also you should not be affected if your umask is 002 (group write enabled) - this is the default on many linux systems. Recommendation for users using Airflow outside of the containers: * if you are using root to run Airflow, change your Airflow user to use non-root * upgrade Apache Airflow to 2.8.4 or above * If you prefer not to upgrade, you can change the https://airflow.apache.org/docs/apache-airflow/stable/configurations-ref.html#file-task-handler-new-folder-permissions to 0o755 (original value 0o775). * if you already ran Airflow tasks before and your default umask is 022 (group write disabled) you should stop Airflow components, check permissions of AIRFLOW_HOME/logs in all your components and all parent directories of this directory and remove group write access for all the parent directories Affected products apache-airflow =<2.8.3 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2023-47265 created 10 months ago Apache Airflow: DAG Params alllow to embed unchecked Javascript Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of the user who looks at the tasks in the browser sandbox. While this issue does not allow to exit the browser sandbox or manipulation of the server-side data - more than the DAG author already has, it allows to modify what the user looking at the DAG details sees in the browser - which opens up all kinds of possibilities of misleading other users. Users of Apache Airflow are recommended to upgrade to version 2.8.0 or newer to mitigate the risk associated with this vulnerability Affected products apache-airflow <2.8.0 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2023-3354 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 10 months ago Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service. Affected products qemu qemu-kvm qemu-kvm-ma qemu-kvm-rhev virt:av/qemu-kvm virt:rhel/qemu-kvm Matching in nixpkgs pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable 0-unstable-2023-06-06 nixos-unstable-small 0-unstable-2023-06-06 nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable x86_defconfig-2024.10 nixos-unstable-small x86_defconfig-2024.10 nixpkgs-unstable x86_defconfig-2024.10 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable qemu_arm64_defconfig-2024.10 nixos-unstable-small qemu_arm64_defconfig-2024.10 nixpkgs-unstable qemu_arm64_defconfig-2024.10 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.qemu.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_xen.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable 2.10.0 nixos-unstable-small 2.10.0 nixpkgs-unstable 2.10.0 pkgs.python311Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.qemu-user.x86_64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 pkgs.qemu_full.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-user.aarch64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 pkgs.qemu-utils.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-python-utils.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 Package maintainers: 10 @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @DavHau David Hauer <d.hauer.it@gmail.com> @bartsch Daniel Martin <consume.noise@gmail.com> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @oxalica oxalica <oxalicc@pm.me> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @CertainLach Yaroslav Bolyukin <iam@lach.pw> @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net>
pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable 0-unstable-2023-06-06 nixos-unstable-small 0-unstable-2023-06-06 nixpkgs-unstable 0-unstable-2023-06-06
pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable x86_defconfig-2024.10 nixos-unstable-small x86_defconfig-2024.10 nixpkgs-unstable x86_defconfig-2024.10
pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable qemu_arm64_defconfig-2024.10 nixos-unstable-small qemu_arm64_defconfig-2024.10 nixpkgs-unstable qemu_arm64_defconfig-2024.10
pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1
pkgs.qemu.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_kvm.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_xen.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable 2.10.0 nixos-unstable-small 2.10.0 nixpkgs-unstable 2.10.0
pkgs.python311Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1
pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1
pkgs.qemu-user.x86_64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1
pkgs.qemu_full.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_kvm.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_kvm.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_test.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-user.aarch64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1
pkgs.qemu-utils.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_full.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_full.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_kvm.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_test.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_test.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-utils.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-utils.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_full.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_test.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-utils.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-python-utils.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.qemu-python-utils.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.qemu-python-utils.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.qemu-python-utils.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.python312Packages.qemu.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.python312Packages.qemu.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.python312Packages.qemu.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.python312Packages.qemu.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
CVE-2023-47248 created 10 months ago PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This vulnerability only affects PyArrow, not other Apache Arrow implementations or bindings. It is recommended that users of PyArrow upgrade to 14.0.1. Similarly, it is recommended that downstream libraries upgrade their dependency requirements to PyArrow 14.0.1 or later. PyPI packages are already available, and we hope that conda-forge packages will be available soon. If it is not possible to upgrade, we provide a separate package `pyarrow-hotfix` that disables the vulnerability on older PyArrow versions. See https://pypi.org/project/pyarrow-hotfix/ for instructions. Affected products pyarrow =<14.0.0 Matching in nixpkgs pkgs.python311Packages.pyarrow Cross-language development platform for in-memory data nixos-unstable 18.0.0 nixos-unstable-small 18.0.0 nixpkgs-unstable 18.0.0 pkgs.python312Packages.pyarrow Cross-language development platform for in-memory data nixos-unstable 18.0.0 nixos-unstable-small 18.0.0 nixpkgs-unstable 18.0.0 pkgs.python311Packages.pyarrow-hotfix Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6 nixos-unstable-small 0.6 nixpkgs-unstable 0.6 pkgs.python312Packages.pyarrow-hotfix Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6 nixos-unstable-small 0.6 nixpkgs-unstable 0.6 pkgs.python311Packages.geoarrow-pyarrow PyArrow implementation of geospatial data types nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2 pkgs.python312Packages.geoarrow-pyarrow PyArrow implementation of geospatial data types nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2 pkgs.python312Packages.pyarrow.x86_64-linux Cross-language development platform for in-memory data nixos-unstable 18.0.0 pkgs.python312Packages.pyarrow.aarch64-linux Cross-language development platform for in-memory data nixos-unstable 18.0.0 pkgs.python312Packages.pyarrow.x86_64-darwin Cross-language development platform for in-memory data nixos-unstable 18.0.0 pkgs.python312Packages.pyarrow.aarch64-darwin Cross-language development platform for in-memory data nixos-unstable 18.0.0 pkgs.python312Packages.pyarrow-hotfix.x86_64-linux Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6 pkgs.python312Packages.pyarrow-hotfix.aarch64-linux Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6 pkgs.python312Packages.pyarrow-hotfix.x86_64-darwin Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6 pkgs.python312Packages.geoarrow-pyarrow.x86_64-linux PyArrow implementation of geospatial data types nixos-unstable 0.1.2 pkgs.python312Packages.pyarrow-hotfix.aarch64-darwin Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6 pkgs.python312Packages.geoarrow-pyarrow.aarch64-linux PyArrow implementation of geospatial data types nixos-unstable 0.1.2 pkgs.python312Packages.geoarrow-pyarrow.x86_64-darwin PyArrow implementation of geospatial data types nixos-unstable 0.1.2 pkgs.python312Packages.geoarrow-pyarrow.aarch64-darwin PyArrow implementation of geospatial data types nixos-unstable 0.1.2 Package maintainers: 3 @cpcloud Phillip Cloud @veprbl Dmitry Kalinkin <veprbl@gmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch>
pkgs.python311Packages.pyarrow Cross-language development platform for in-memory data nixos-unstable 18.0.0 nixos-unstable-small 18.0.0 nixpkgs-unstable 18.0.0
pkgs.python312Packages.pyarrow Cross-language development platform for in-memory data nixos-unstable 18.0.0 nixos-unstable-small 18.0.0 nixpkgs-unstable 18.0.0
pkgs.python311Packages.pyarrow-hotfix Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6 nixos-unstable-small 0.6 nixpkgs-unstable 0.6
pkgs.python312Packages.pyarrow-hotfix Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6 nixos-unstable-small 0.6 nixpkgs-unstable 0.6
pkgs.python311Packages.geoarrow-pyarrow PyArrow implementation of geospatial data types nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2
pkgs.python312Packages.geoarrow-pyarrow PyArrow implementation of geospatial data types nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2
pkgs.python312Packages.pyarrow.x86_64-linux Cross-language development platform for in-memory data nixos-unstable 18.0.0
pkgs.python312Packages.pyarrow.aarch64-linux Cross-language development platform for in-memory data nixos-unstable 18.0.0
pkgs.python312Packages.pyarrow.x86_64-darwin Cross-language development platform for in-memory data nixos-unstable 18.0.0
pkgs.python312Packages.pyarrow.aarch64-darwin Cross-language development platform for in-memory data nixos-unstable 18.0.0
pkgs.python312Packages.pyarrow-hotfix.x86_64-linux Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6
pkgs.python312Packages.pyarrow-hotfix.aarch64-linux Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6
pkgs.python312Packages.pyarrow-hotfix.x86_64-darwin Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6
pkgs.python312Packages.geoarrow-pyarrow.x86_64-linux PyArrow implementation of geospatial data types nixos-unstable 0.1.2
pkgs.python312Packages.pyarrow-hotfix.aarch64-darwin Hotfix for the PyArrow security vulnerability CVE-2023-47248 nixos-unstable 0.6
pkgs.python312Packages.geoarrow-pyarrow.aarch64-linux PyArrow implementation of geospatial data types nixos-unstable 0.1.2
pkgs.python312Packages.geoarrow-pyarrow.x86_64-darwin PyArrow implementation of geospatial data types nixos-unstable 0.1.2
pkgs.python312Packages.geoarrow-pyarrow.aarch64-darwin PyArrow implementation of geospatial data types nixos-unstable 0.1.2