Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2024-45619 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 9 months, 4 weeks ago Libopensc: incorrect handling length of buffers or files in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0 pkgs.openscad 3D parametric model compiler nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable 1.3.10 nixos-unstable-small 1.3.10 nixpkgs-unstable 1.3.10 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5 pkgs.openscenegraph 3D graphics toolkit nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06 pkgs.vimPlugins.vim-openscad nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26 pkgs.vimPlugins.openscad-nvim nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13 pkgs.kakounePlugins.openscad-kak nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1 pkgs.vimPlugins.vim-openscad.x86_64-linux nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.aarch64-linux nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.x86_64-darwin nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.aarch64-darwin nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vscode-extensions.antyos.openscad.x86_64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.aarch64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.x86_64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.aarch64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @gebner Gabriel Ebner <gebner@gebner.org> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2024-45618 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 9 months, 4 weeks ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15init A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0 pkgs.openscad 3D parametric model compiler nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable 1.3.10 nixpkgs-unstable 1.3.10 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5 pkgs.openscenegraph 3D graphics toolkit nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06 pkgs.vimPlugins.vim-openscad nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26 pkgs.vimPlugins.openscad-nvim nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13 pkgs.kakounePlugins.openscad-kak nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1 pkgs.vimPlugins.vim-openscad.x86_64-linux nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.aarch64-linux nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.x86_64-darwin nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.aarch64-darwin nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vscode-extensions.antyos.openscad.x86_64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.aarch64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.x86_64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.aarch64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 Package maintainers: 8 @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @gebner Gabriel Ebner <gebner@gebner.org> CVE-2024-2905 6.2 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 10 months ago Rpm-ostree: world-readable /etc/shadow file A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, potentially exposing sensitive authentication data to unauthorized access. rpm-ostree * ==1.2024.4 pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8 pkgs.rpm-ostree.x86_64-linux Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8 pkgs.rpm-ostree.aarch64-linux Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8 Package maintainers: 1 @copumpkin Dan Peebles <pumpkingod@gmail.com> CVE-2024-3049 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): NONE created 10 months ago Booth: specially crafted hash can lead to invalid hmac being accepted by booth server A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server. booth ==1.0-283.1 * pkgs.libsForQt5.booth Camera application nixos-unstable 1.1.3 nixos-unstable-small 1.1.3 nixpkgs-unstable 1.1.3 pkgs.plasma5Packages.booth Camera application nixos-unstable 1.1.3 nixos-unstable-small 1.1.3 nixpkgs-unstable 1.1.3 pkgs.libsForQt5.booth.x86_64-linux Camera application nixos-unstable ??? nixos-unstable-small 1.1.3 pkgs.libsForQt5.booth.aarch64-linux Camera application nixos-unstable ??? nixos-unstable-small 1.1.3 pkgs.plasma5Packages.booth.x86_64-linux Camera application nixos-unstable ??? nixpkgs-unstable 1.1.3 pkgs.plasma5Packages.booth.aarch64-linux Camera application nixos-unstable ??? nixpkgs-unstable 1.1.3 Package maintainers: 1 @milahu Milan Hauth <milahu@gmail.com> CVE-2024-47515 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 10 months ago Pagure: generate_archive() follows symbolic links in temporary clones A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance. pagure ==5.14.1 pkgs.haskellPackages.pagure Pagure REST client library nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2 pkgs.haskellPackages.pagure-cli Pagure client nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1 CVE-2024-4871 6.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 10 months ago Foreman: host ssh key not being checked in remote execution A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it. foreman * ==3.9.1.8 candlepin * satellite * python-pulpcore * rubygem-dynflow * rubygem-katello * foreman-installer * python-pulp-container * rubygem-foreman_ansible * rubygem-foreman_remote_execution * rubygem-smart_proxy_container_gateway * rubygem-smart_proxy_remote_execution_ssh * pkgs.foreman Process manager for applications with multiple components nixos-unstable 0.87.2 nixos-unstable-small 0.87.2 nixpkgs-unstable 0.87.2 pkgs.satellite Program for showing navigation satellite data nixos-unstable 0.9.0 nixos-unstable-small 0.9.0 nixpkgs-unstable 0.9.0 pkgs.wyoming-satellite Remote voice satellite using Wyoming protocol nixos-unstable 1.2.0 nixos-unstable-small 1.2.0 nixpkgs-unstable 1.2.0 pkgs.xwayland-satellite Xwayland outside your Wayland compositor nixos-unstable 0.5 nixos-unstable-small 0.5 nixpkgs-unstable 0.5 pkgs.satellite.x86_64-linux Program for showing navigation satellite data nixos-unstable 0.9.0 pkgs.homeassistant-satellite Streaming audio satellite for Home Assistant nixos-unstable 2.3.0 nixos-unstable-small 2.3.0 nixpkgs-unstable 2.3.0 pkgs.satellite.aarch64-linux Program for showing navigation satellite data nixos-unstable 0.9.0 pkgs.vimPlugins.satellite-nvim nixos-unstable 2024-11-20 nixos-unstable-small 2024-12-05 nixpkgs-unstable 2024-11-20 pkgs.emacsPackages.foreman-mode nixos-unstable 20170725.1422 nixos-unstable-small 20170725.1422 nixpkgs-unstable 20170725.1422 pkgs.home-assistant-component-tests.assist_satellite Open source home automation that puts local control and privacy first nixos-unstable 2024.11.3 nixos-unstable-small 2024.11.3 nixpkgs-unstable 2024.11.3 Package maintainers: 8 @zimbatm zimbatm <zimbatm@zimbatm.com> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @Mic92 Jörg Thalheim <joerg@thalheim.io> @Luflosi Luflosi <luflosi@luflosi.de> @sodiboo sodiboo @if-loop69420 Jeremy Sztavinovszki <j.sztavi@pm.me> @getchoo Seth Flynn <getchoo@tuta.io> CVE-2024-9666 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 10 months ago Org.keycloak/keycloak-quarkus-server: keycloak proxy header handling denial-of-service (dos) vulnerability A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers. keycloak <24.0.9 <26.0.6 rhbk/keycloak-rhel9 * rhbk/keycloak-rhel9-operator * rhbk/keycloak-operator-bundle * org.keycloak/keycloak-quarkus-server pkgs.keycloak Identity and access management for modern applications and services nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6 pkgs.terraform-providers.keycloak nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0 pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak.x86_64-linux Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.aarch64-linux Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.x86_64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.aarch64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0 Package maintainers: 3 @NickCao Nick Cao <nickcao@nichi.co> @talyz Kim Lindberger <kim.lindberger@gmail.com> @ngerstle Nicholas Gerstle <ngerstle@gmail.com> CVE-2024-4629 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 10 months ago Keycloak: potential bypass of brute force protection A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems. keycloak ==24.0.3 rh-sso7-keycloak * rhbk/keycloak-rhel9 * org.keycloak-keycloak-parent rhbk/keycloak-rhel9-operator * rhbk/keycloak-operator-bundle * rh-sso-7/sso76-openshift-rhel8 * pkgs.keycloak Identity and access management for modern applications and services nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6 pkgs.terraform-providers.keycloak nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0 pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak.x86_64-linux Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.aarch64-linux Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.x86_64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.aarch64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0 Package maintainers: 3 @NickCao Nick Cao <nickcao@nichi.co> @talyz Kim Lindberger <kim.lindberger@gmail.com> @ngerstle Nicholas Gerstle <ngerstle@gmail.com> CVE-2024-2199 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 10 months ago 389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.c A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input. 389-ds:1.4 * 389-ds-base * <3.1.1 redhat-ds:11 * redhat-ds:12 * 389-ds:1.4/389-ds-base redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable 3.1.1 nixos-unstable-small 3.1.1 nixpkgs-unstable 3.1.1 Package maintainers: 1 @ners ners <ners@gmx.ch> CVE-2024-9427 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 10 months ago Koji: escape html tag characters in the query string A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code koji <1.35.1 pkgs.koji Interactive CLI for creating conventional commits nixos-unstable 2.2.0 nixos-unstable-small 2.2.0 nixpkgs-unstable 2.2.0 pkgs.haskellPackages.koji Koji buildsystem XML-RPC API bindings nixos-unstable 0.0.2 nixos-unstable-small 0.0.2 nixpkgs-unstable 0.0.2 pkgs.haskellPackages.koji.x86_64-linux Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2 pkgs.haskellPackages.koji.aarch64-linux Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2 pkgs.haskellPackages.koji.x86_64-darwin Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2 pkgs.haskellPackages.koji.aarch64-darwin Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2 Package maintainers: 1 @ByteSudoer ByteSudoer <bytesudoer@gmail.com>
CVE-2024-45619 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 9 months, 4 weeks ago Libopensc: incorrect handling length of buffers or files in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0 pkgs.openscad 3D parametric model compiler nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable 1.3.10 nixos-unstable-small 1.3.10 nixpkgs-unstable 1.3.10 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5 pkgs.openscenegraph 3D graphics toolkit nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06 pkgs.vimPlugins.vim-openscad nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26 pkgs.vimPlugins.openscad-nvim nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13 pkgs.kakounePlugins.openscad-kak nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1 pkgs.vimPlugins.vim-openscad.x86_64-linux nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.aarch64-linux nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.x86_64-darwin nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.aarch64-darwin nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vscode-extensions.antyos.openscad.x86_64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.aarch64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.x86_64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.aarch64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @gebner Gabriel Ebner <gebner@gebner.org> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0
pkgs.openscad 3D parametric model compiler nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01
pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable 1.3.10 nixos-unstable-small 1.3.10 nixpkgs-unstable 1.3.10
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5
pkgs.openscenegraph 3D graphics toolkit nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06
pkgs.vimPlugins.vim-openscad nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26
pkgs.vimPlugins.openscad-nvim nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13
pkgs.kakounePlugins.openscad-kak nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1
pkgs.vscode-extensions.antyos.openscad.x86_64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1
pkgs.vscode-extensions.antyos.openscad.aarch64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1
pkgs.vscode-extensions.antyos.openscad.x86_64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1
pkgs.vscode-extensions.antyos.openscad.aarch64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1
CVE-2024-45618 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 9 months, 4 weeks ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15init A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0 pkgs.openscad 3D parametric model compiler nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable 1.3.10 nixpkgs-unstable 1.3.10 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5 pkgs.openscenegraph 3D graphics toolkit nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06 pkgs.vimPlugins.vim-openscad nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26 pkgs.vimPlugins.openscad-nvim nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13 pkgs.kakounePlugins.openscad-kak nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1 pkgs.vimPlugins.vim-openscad.x86_64-linux nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.aarch64-linux nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.x86_64-darwin nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vimPlugins.vim-openscad.aarch64-darwin nixos-unstable ??? nixos-unstable-small 2022-07-26 pkgs.vscode-extensions.antyos.openscad.x86_64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.aarch64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.x86_64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 pkgs.vscode-extensions.antyos.openscad.aarch64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1 Package maintainers: 8 @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @gebner Gabriel Ebner <gebner@gebner.org>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable 0.26.0 nixos-unstable-small 0.26.0 nixpkgs-unstable 0.26.0
pkgs.openscad 3D parametric model compiler nixos-unstable 2021.01 nixos-unstable-small 2021.01 nixpkgs-unstable 2021.01
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable 1.2.5 nixos-unstable-small 1.2.5 nixpkgs-unstable 1.2.5
pkgs.openscenegraph 3D graphics toolkit nixos-unstable 3.6.5 nixos-unstable-small 3.6.5 nixpkgs-unstable 3.6.5
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable 2024-12-06 nixos-unstable-small 2024-12-06 nixpkgs-unstable 2024-12-06
pkgs.vimPlugins.vim-openscad nixos-unstable 2022-07-26 nixos-unstable-small 2022-07-26 nixpkgs-unstable 2022-07-26
pkgs.vimPlugins.openscad-nvim nixos-unstable 2024-04-13 nixos-unstable-small 2024-04-13 nixpkgs-unstable 2024-04-13
pkgs.kakounePlugins.openscad-kak nixos-unstable 2020-12-10 nixos-unstable-small 2020-12-10 nixpkgs-unstable 2020-12-10
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable 1.3.1 nixos-unstable-small 1.3.1 nixpkgs-unstable 1.3.1
pkgs.vscode-extensions.antyos.openscad.x86_64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1
pkgs.vscode-extensions.antyos.openscad.aarch64-linux OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1
pkgs.vscode-extensions.antyos.openscad.x86_64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1
pkgs.vscode-extensions.antyos.openscad.aarch64-darwin OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixos-unstable-small 1.3.1
CVE-2024-2905 6.2 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 10 months ago Rpm-ostree: world-readable /etc/shadow file A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, potentially exposing sensitive authentication data to unauthorized access. rpm-ostree * ==1.2024.4 pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8 pkgs.rpm-ostree.x86_64-linux Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8 pkgs.rpm-ostree.aarch64-linux Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8 Package maintainers: 1 @copumpkin Dan Peebles <pumpkingod@gmail.com>
pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8
pkgs.rpm-ostree.x86_64-linux Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8
pkgs.rpm-ostree.aarch64-linux Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable 2024.8
CVE-2024-3049 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): NONE created 10 months ago Booth: specially crafted hash can lead to invalid hmac being accepted by booth server A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server. booth ==1.0-283.1 * pkgs.libsForQt5.booth Camera application nixos-unstable 1.1.3 nixos-unstable-small 1.1.3 nixpkgs-unstable 1.1.3 pkgs.plasma5Packages.booth Camera application nixos-unstable 1.1.3 nixos-unstable-small 1.1.3 nixpkgs-unstable 1.1.3 pkgs.libsForQt5.booth.x86_64-linux Camera application nixos-unstable ??? nixos-unstable-small 1.1.3 pkgs.libsForQt5.booth.aarch64-linux Camera application nixos-unstable ??? nixos-unstable-small 1.1.3 pkgs.plasma5Packages.booth.x86_64-linux Camera application nixos-unstable ??? nixpkgs-unstable 1.1.3 pkgs.plasma5Packages.booth.aarch64-linux Camera application nixos-unstable ??? nixpkgs-unstable 1.1.3 Package maintainers: 1 @milahu Milan Hauth <milahu@gmail.com>
pkgs.libsForQt5.booth Camera application nixos-unstable 1.1.3 nixos-unstable-small 1.1.3 nixpkgs-unstable 1.1.3
pkgs.plasma5Packages.booth Camera application nixos-unstable 1.1.3 nixos-unstable-small 1.1.3 nixpkgs-unstable 1.1.3
pkgs.plasma5Packages.booth.aarch64-linux Camera application nixos-unstable ??? nixpkgs-unstable 1.1.3
CVE-2024-47515 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 10 months ago Pagure: generate_archive() follows symbolic links in temporary clones A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance. pagure ==5.14.1 pkgs.haskellPackages.pagure Pagure REST client library nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2 pkgs.haskellPackages.pagure-cli Pagure client nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1
pkgs.haskellPackages.pagure Pagure REST client library nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2
pkgs.haskellPackages.pagure-cli Pagure client nixos-unstable 0.2.1 nixos-unstable-small 0.2.1 nixpkgs-unstable 0.2.1
CVE-2024-4871 6.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 10 months ago Foreman: host ssh key not being checked in remote execution A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it. foreman * ==3.9.1.8 candlepin * satellite * python-pulpcore * rubygem-dynflow * rubygem-katello * foreman-installer * python-pulp-container * rubygem-foreman_ansible * rubygem-foreman_remote_execution * rubygem-smart_proxy_container_gateway * rubygem-smart_proxy_remote_execution_ssh * pkgs.foreman Process manager for applications with multiple components nixos-unstable 0.87.2 nixos-unstable-small 0.87.2 nixpkgs-unstable 0.87.2 pkgs.satellite Program for showing navigation satellite data nixos-unstable 0.9.0 nixos-unstable-small 0.9.0 nixpkgs-unstable 0.9.0 pkgs.wyoming-satellite Remote voice satellite using Wyoming protocol nixos-unstable 1.2.0 nixos-unstable-small 1.2.0 nixpkgs-unstable 1.2.0 pkgs.xwayland-satellite Xwayland outside your Wayland compositor nixos-unstable 0.5 nixos-unstable-small 0.5 nixpkgs-unstable 0.5 pkgs.satellite.x86_64-linux Program for showing navigation satellite data nixos-unstable 0.9.0 pkgs.homeassistant-satellite Streaming audio satellite for Home Assistant nixos-unstable 2.3.0 nixos-unstable-small 2.3.0 nixpkgs-unstable 2.3.0 pkgs.satellite.aarch64-linux Program for showing navigation satellite data nixos-unstable 0.9.0 pkgs.vimPlugins.satellite-nvim nixos-unstable 2024-11-20 nixos-unstable-small 2024-12-05 nixpkgs-unstable 2024-11-20 pkgs.emacsPackages.foreman-mode nixos-unstable 20170725.1422 nixos-unstable-small 20170725.1422 nixpkgs-unstable 20170725.1422 pkgs.home-assistant-component-tests.assist_satellite Open source home automation that puts local control and privacy first nixos-unstable 2024.11.3 nixos-unstable-small 2024.11.3 nixpkgs-unstable 2024.11.3 Package maintainers: 8 @zimbatm zimbatm <zimbatm@zimbatm.com> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @Mic92 Jörg Thalheim <joerg@thalheim.io> @Luflosi Luflosi <luflosi@luflosi.de> @sodiboo sodiboo @if-loop69420 Jeremy Sztavinovszki <j.sztavi@pm.me> @getchoo Seth Flynn <getchoo@tuta.io>
pkgs.foreman Process manager for applications with multiple components nixos-unstable 0.87.2 nixos-unstable-small 0.87.2 nixpkgs-unstable 0.87.2
pkgs.satellite Program for showing navigation satellite data nixos-unstable 0.9.0 nixos-unstable-small 0.9.0 nixpkgs-unstable 0.9.0
pkgs.wyoming-satellite Remote voice satellite using Wyoming protocol nixos-unstable 1.2.0 nixos-unstable-small 1.2.0 nixpkgs-unstable 1.2.0
pkgs.xwayland-satellite Xwayland outside your Wayland compositor nixos-unstable 0.5 nixos-unstable-small 0.5 nixpkgs-unstable 0.5
pkgs.homeassistant-satellite Streaming audio satellite for Home Assistant nixos-unstable 2.3.0 nixos-unstable-small 2.3.0 nixpkgs-unstable 2.3.0
pkgs.vimPlugins.satellite-nvim nixos-unstable 2024-11-20 nixos-unstable-small 2024-12-05 nixpkgs-unstable 2024-11-20
pkgs.emacsPackages.foreman-mode nixos-unstable 20170725.1422 nixos-unstable-small 20170725.1422 nixpkgs-unstable 20170725.1422
pkgs.home-assistant-component-tests.assist_satellite Open source home automation that puts local control and privacy first nixos-unstable 2024.11.3 nixos-unstable-small 2024.11.3 nixpkgs-unstable 2024.11.3
CVE-2024-9666 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 10 months ago Org.keycloak/keycloak-quarkus-server: keycloak proxy header handling denial-of-service (dos) vulnerability A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers. keycloak <24.0.9 <26.0.6 rhbk/keycloak-rhel9 * rhbk/keycloak-rhel9-operator * rhbk/keycloak-operator-bundle * org.keycloak/keycloak-quarkus-server pkgs.keycloak Identity and access management for modern applications and services nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6 pkgs.terraform-providers.keycloak nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0 pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak.x86_64-linux Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.aarch64-linux Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.x86_64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.aarch64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0 Package maintainers: 3 @NickCao Nick Cao <nickcao@nichi.co> @talyz Kim Lindberger <kim.lindberger@gmail.com> @ngerstle Nicholas Gerstle <ngerstle@gmail.com>
pkgs.keycloak Identity and access management for modern applications and services nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6
pkgs.terraform-providers.keycloak nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0
pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.python312Packages.python-keycloak.x86_64-linux Provides access to the Keycloak API nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.aarch64-linux Provides access to the Keycloak API nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.x86_64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.aarch64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0
CVE-2024-4629 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 10 months ago Keycloak: potential bypass of brute force protection A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems. keycloak ==24.0.3 rh-sso7-keycloak * rhbk/keycloak-rhel9 * org.keycloak-keycloak-parent rhbk/keycloak-rhel9-operator * rhbk/keycloak-operator-bundle * rh-sso-7/sso76-openshift-rhel8 * pkgs.keycloak Identity and access management for modern applications and services nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6 pkgs.terraform-providers.keycloak nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0 pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0 pkgs.python312Packages.python-keycloak.x86_64-linux Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.aarch64-linux Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.x86_64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0 pkgs.python312Packages.python-keycloak.aarch64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0 Package maintainers: 3 @NickCao Nick Cao <nickcao@nichi.co> @talyz Kim Lindberger <kim.lindberger@gmail.com> @ngerstle Nicholas Gerstle <ngerstle@gmail.com>
pkgs.keycloak Identity and access management for modern applications and services nixos-unstable 26.0.6 nixos-unstable-small 26.0.7 nixpkgs-unstable 26.0.6
pkgs.terraform-providers.keycloak nixos-unstable 4.4.0 nixos-unstable-small 4.4.0 nixpkgs-unstable 4.4.0
pkgs.python311Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable 4.0.0 nixos-unstable-small 4.0.0 nixpkgs-unstable 4.0.0
pkgs.python312Packages.python-keycloak.x86_64-linux Provides access to the Keycloak API nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.aarch64-linux Provides access to the Keycloak API nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.x86_64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.aarch64-darwin Provides access to the Keycloak API nixos-unstable 4.0.0
CVE-2024-2199 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): ADJACENT_NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 10 months ago 389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.c A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input. 389-ds:1.4 * 389-ds-base * <3.1.1 redhat-ds:11 * redhat-ds:12 * 389-ds:1.4/389-ds-base redhat-ds:11/389-ds-base redhat-ds:12/389-ds-base pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable 3.1.1 nixos-unstable-small 3.1.1 nixpkgs-unstable 3.1.1 Package maintainers: 1 @ners ners <ners@gmx.ch>
pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable 3.1.1 nixos-unstable-small 3.1.1 nixpkgs-unstable 3.1.1
CVE-2024-9427 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 10 months ago Koji: escape html tag characters in the query string A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code koji <1.35.1 pkgs.koji Interactive CLI for creating conventional commits nixos-unstable 2.2.0 nixos-unstable-small 2.2.0 nixpkgs-unstable 2.2.0 pkgs.haskellPackages.koji Koji buildsystem XML-RPC API bindings nixos-unstable 0.0.2 nixos-unstable-small 0.0.2 nixpkgs-unstable 0.0.2 pkgs.haskellPackages.koji.x86_64-linux Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2 pkgs.haskellPackages.koji.aarch64-linux Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2 pkgs.haskellPackages.koji.x86_64-darwin Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2 pkgs.haskellPackages.koji.aarch64-darwin Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2 Package maintainers: 1 @ByteSudoer ByteSudoer <bytesudoer@gmail.com>
pkgs.koji Interactive CLI for creating conventional commits nixos-unstable 2.2.0 nixos-unstable-small 2.2.0 nixpkgs-unstable 2.2.0
pkgs.haskellPackages.koji Koji buildsystem XML-RPC API bindings nixos-unstable 0.0.2 nixos-unstable-small 0.0.2 nixpkgs-unstable 0.0.2
pkgs.haskellPackages.koji.x86_64-linux Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2
pkgs.haskellPackages.koji.aarch64-linux Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2
pkgs.haskellPackages.koji.x86_64-darwin Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2
pkgs.haskellPackages.koji.aarch64-darwin Koji buildsystem XML-RPC API bindings nixos-unstable ??? nixpkgs-unstable 0.0.2