Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-20336
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Resource Lifetime Management Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20336 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

Affected products

Cisco Secure Firewall Management Center (FMC)
  • ==7.6.2.1
  • ==7.4.2.1
  • ==7.7.12
  • ==7.2.8.1
  • ==7.0.9
  • ==7.0.4
  • ==7.3.1
  • ==7.6.0
  • ==7.4.2.3
  • ==7.2.10.1
  • ==7.0.3
  • ==7.0.5
  • ==7.7.0
  • ==7.0.6.1
  • ==7.6.3
  • ==10.0.1
  • ==7.2.2
  • ==7.2.4
  • ==7.2.0.1
  • ==7.2.9
  • ==7.2.1
  • ==7.4.4
  • ==7.7.10.1
  • ==7.0.8
  • ==7.2.6
  • ==7.0.6.3
  • ==7.6.1
  • ==7.4.2.4
  • ==7.4.0
  • ==7.4.5
  • ==7.4.2.2
  • ==7.2.3.1
  • ==7.2.5.2
  • ==7.2.3
  • ==7.7.10
  • ==7.0.1
  • ==7.0.2
  • ==7.3.1.1
  • ==7.0.0
  • ==7.6.4
  • ==7.2.10
  • ==10.0.0
  • ==7.0.6.2
  • ==7.4.6
  • ==7.2.11
  • ==7.6.2
  • ==7.2.0
  • ==7.0.1.1
  • ==7.0.8.1
  • ==7.0.2.1
  • ==7.2.5
  • ==7.0.6
  • ==7.2.8
  • ==7.0.7
  • ==7.4.3
  • ==7.7.11
  • ==7.2.7
  • ==7.3.1.2
  • ==7.6.5
  • ==7.2.10.2
  • ==7.2.5.1
  • ==7.4.1
  • ==7.4.1.1
  • ==7.2.4.1
  • ==7.4.2
  • ==7.3.0
  • ==7.4.7
  • ==7.0.0.1
Cisco Secure Firewall Threat Defense (FTD) Software
  • ==7.6.2.1
  • ==7.4.2.1
  • ==7.0.9
  • ==7.0.4
  • ==7.3.1
  • ==7.6.0
  • ==7.4.2.3
  • ==7.0.3
  • ==7.0.5
  • ==7.7.0
  • ==7.0.6.1
  • ==7.4.4
  • ==7.7.10.1
  • ==7.0.8
  • ==7.0.6.3
  • ==7.6.1
  • ==7.4.2.4
  • ==7.4.0
  • ==7.4.2.2
  • ==7.7.10
  • ==7.0.1
  • ==7.0.2
  • ==7.3.1.1
  • ==7.6.4
  • ==10.0.0
  • ==7.0.6.2
  • ==7.6.2
  • ==7.0.1.1
  • ==7.0.8.1
  • ==7.0.2.1
  • ==7.0.6
  • ==7.7.11
  • ==7.0.7
  • ==7.4.3
  • ==7.3.1.2
  • ==7.4.1
  • ==7.4.1.1
  • ==7.4.2
  • ==7.3.0
  • ==7.4.7
  • ==7.0.0.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • ==9.22.2
  • ==9.18.4.47
  • ==9.16.3.14
  • ==9.16.4.55
  • ==9.22.2.14
  • ==9.23.1.22
  • ==9.20.4.19
  • ==9.18.4.68
  • ==9.16.4.71
  • ==9.23.1.19
  • ==9.19.1.42
  • ==9.23.1.32
  • ==9.18.4.5
  • ==9.18.1.3
  • ==9.22.1.6
  • ==9.20.4.22
  • ==9.20.3
  • ==9.18.4.67
  • ==9.18.4.24
  • ==9.18.4.53
  • ==9.22.2.13
  • ==9.24.1.221
  • ==9.20.4.30
  • ==9.23.1.211
  • ==9.18.2.7
  • ==9.18.4
  • ==9.16.4.18
  • ==9.22.1.2
  • ==9.20.1.5
  • ==9.23.1.26
  • ==9.16.4.61
  • ==9.16.4.92
  • ==9.18.4.29
  • ==9.22.2.9
  • ==9.24.1.9
  • ==9.18.4.57
  • ==9.18.3.55
  • ==9.18.2.5
  • ==9.23.1.13
  • ==9.16.2.13
  • ==9.20.3.4
  • ==9.16.3
  • ==9.22.2.20
  • ==9.23.1.195
  • ==9.16.4.82
  • ==9.20.2.21
  • ==9.22.2.32
  • ==9.20.4.34
  • ==9.16.4.85
  • ==9.18.4.40
  • ==9.22.1.3
  • ==9.20.3.20
  • ==9.18.4.82
  • ==9.22.3.191
  • ==9.16.3.19
  • ==9.16.2
  • ==9.18.4.50
  • ==9.23.1.7
  • ==9.20.4.7
  • ==9.16.4.89
  • ==9.20.3.7
  • ==9.16.4.67
  • ==9.20.4.28
  • ==9.16.3.15
  • ==9.16.3.23
  • ==9.18.4.76
  • ==9.20.4.10
  • ==9.18.4.71
  • ==9.24.1.5
  • ==9.16.4.70
  • ==9.16.4.62
  • ==9.22.2.4
  • ==9.20.3.16
  • ==9.16.4.19
  • ==9.16.4.39
  • ==9.20.1
  • ==9.22.3
  • ==9.24.1
  • ==9.18.4.66
  • ==9.16.4.9
  • ==9.24.1.155
  • ==9.16.2.7
  • ==9.16.4.48
  • ==9.20.2.22
  • ==9.16.4.38
  • ==9.24.1.11
  • ==9.16.4.27
  • ==9.23.1
  • ==9.20.3.10
  • ==9.16.4
  • ==9.16.4.76
  • ==9.18.3.39
  • ==9.16.4.84
  • ==9.18.3.46
  • ==9.18.4.52
  • ==9.16.2.14
  • ==9.23.1.3
  • ==9.18.2.8
  • ==9.16.1.28
  • ==9.16.2.3
  • ==9.18.2
  • ==9.16.2.11
  • ==9.18.4.8
  • ==9.22.1.1
  • ==9.22.3.5
  • ==9.16.4.14
  • ==9.20.4
  • ==9.20.3.13
  • ==9.18.4.22
  • ==9.18.4.34
  • ==9.20.4.14
  • ==9.20.2.10
  • ==9.18.3
  • ==9.16.4.57
  • ==9.16.3.3
  • ==9.20.3.9
  • ==9.18.3.56
  • ==9.16.1
  • ==9.18.4.135
  • ==9.20.4.235
  • ==9.20.2
  • ==9.24.10
  • ==9.16.4.42
  • ==9.18.3.53
Dismissed
(no matching packages found)
Permalink CVE-2026-92141
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict …

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

References

Affected products

Jenkins Keycloak Authentication Plugin
  • =<2.4.1
Dismissed
(no matching packages found)
Permalink CVE-2026-76412
8.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Secure Firewall Management Center Software Authenticated Privilege Escalation to Root Vulnerability

A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service. This vulnerability is due to an error when checking the privilege level of a user who is invoking remote diagnostics. An attacker could exploit this vulnerability by authenticating to the device, either through the web-based management interface or the REST API, and using the remote diagnostics debugger to grant a user elevated privileges. A successful exploit could allow the attacker to elevate privileges to root. Notes: To exploit this vulnerability, the attacker must have valid user credentials on the affected device. The CVSSv3.1 Attack Complexity is High due to the multistage process required to fully exploit this vulnerability.

Affected products

Cisco Secure Firewall Management Center (FMC)
  • ==7.7.12
  • ==10.0.0
  • ==10.0.1
  • ==7.7.0
  • ==7.7.10
  • ==7.7.10.1
  • ==7.7.11
Dismissed
(no matching packages found)
Permalink CVE-2026-76451
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Identity Services Engine Certificate Management SQL Injection Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials.

Affected products

Cisco ISE Passive Identity Connector
  • ==3.3.0
  • ==3.5.0
  • ==3.4.0
  • ==3.2.0
  • ==3.1.0
Cisco Identity Services Engine Software
  • ==3.1.0 p8
  • ==3.2 Patch 8
  • ==3.3 Patch 9
  • ==3.3.0
  • ==3.4 Patch 3
  • ==3.3 Patch 7
  • ==3.3 Patch 10
  • ==3.2.0
  • ==3.2.0 p4
  • ==3.3 Patch 8
  • ==3.5 Patch 1
  • ==3.3 Patch 2
  • ==3.3 Patch 6
  • ==3.4 Patch 1
  • ==3.1.0 p3
  • ==3.4 Patch 2
  • ==3.1.0 p2
  • ==3.3 Patch 5
  • ==3.2.0 p2
  • ==3.4 Patch 6
  • ==3.2.0 p6
  • ==3.1.0
  • ==3.2.0 p3
  • ==3.2.0 p7
  • ==3.1.0 p4
  • ==3.1.0 p7
  • ==3.3 Patch 4
  • ==3.4 Patch 5
  • ==3.5 Patch 3
  • ==3.1.0 p72
  • ==3.2.0 p1
  • ==3.1.0 p6
  • ==3.3 Patch 1
  • ==3.4.0
  • ==3.2.0 p5
  • ==3.1.0 p10
  • ==3.4 Patch 4
  • ==3.2 Patch 10
  • ==3.1.0 p9
  • ==3.3 Patch 3
  • ==3.5.0
  • ==3.1.0 p11
  • ==3.5 Patch 2
  • ==3.1.0 p1
  • ==3.2 Patch 9
  • ==3.3 Patch 11
  • ==3.1.0 p5
Dismissed
(no matching packages found)
Permalink CVE-2026-20361
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - SQL Injection

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20361 are related to SQL injection issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89.

Affected products

Cisco Nexus Dashboard
  • ==3.2(2f)
  • ==2.1(2f)
  • ==2.3(1c)
  • ==3.2(1e)
  • ==2.2(1e)
  • ==2.3(2b)
  • ==2.3(2e)
  • ==2.3(2c)
  • ==3.0(1i)
  • ==2.1(1e)
  • ==2.1(2d)
  • ==4.2.1
  • ==3.3(2b)
  • ==3.2(1i)
  • ==3.2(2g)
  • ==2.3(2d)
  • ==2.2(2d)
  • ==3.1(1k)
  • ==3.1(1n)
  • ==3.3(1b)
  • ==3.2(2m)
  • ==3.1(1l)
  • ==2.1(1d)
  • ==2.2(1h)
  • ==4.1(1g)
  • ==4.0(1i)
  • ==3.3(2g)
  • ==3.3(1a)
  • ==3.0(1f)
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-89922
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
KVM: s390: Take srcu when importing watchpoint data

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data __import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot update can free the memslots array under us once its SRCU grace period has elapsed. As this is not fast path, following lock ordering (mutex first, then srcu) take the big hammer and hold the srcu for the full import.

Affected products

Linux
  • =<7.2.*
  • <4c05bf21d1806853e662cc19e744736a3408f155
  • =<6.1.*
  • <76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03
  • =<6.12.*
  • <6830fbc3724bf49c142aae69a4694f115fa9cedd
  • =<6.18.*
  • =<*
  • <3.16
  • ==3.16
  • <cc710ee45395efb4937e042960f791d33924e5f6
  • =<6.6.*
  • <f8e3a9997d5ecd56ebe4b262ff424516c068fecb
  • <a4e482def8533ebace517d9f67f1465841b1f982
Dismissed
(max. allowed matches exceeded)
created 1 week, 3 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
f2fs: fix dentry folio leak in find_in_level

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix dentry folio leak in find_in_level find_in_level() gets a dentry folio with f2fs_find_data_folio() before calling find_in_block(). If find_in_block() returns an error, the function stores the error in res_folio and breaks out of the loop without dropping the dentry folio. This leaks the folio reference on the find_in_block() error path. Drop the dentry folio before returning the error to the caller.

Affected products

Linux
  • =<7.2.*
  • <cca7d3e30bf30333314e31bc70b9a739f1342167
  • <5.11
  • ==5.11
  • =<6.18.*
  • =<*
  • <aefb4b0f465b6f95fe02b52d1822a3fb4a9ae922
  • <93a3e6a4c9e726a13a935963e8dc43d181db1527
Dismissed
(no matching packages found)
Permalink CVE-2026-84860
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Scada-LTS DWR Authorization Bypass - Systemic

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which disables DWR's built-in origin validation. This means any authenticated user can invoke any DWR method (regardless of the URL-based access control) by sending their request to a URL they are permitted to access (e.g. MiscDwr.initializeLongPoll.dwr) while targeting a restricted class in the POST body. This is the systemic root cause that enables multiple other findings to be exploited as a low privilege user.

Affected products

Scada-LTS
  • ==2.8.1
Dismissed
(max. allowed matches exceeded)
created 1 week, 3 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
media: s2255: bound JPEG frame size before copying into the buffer

In the Linux kernel, the following vulnerability has been resolved: media: s2255: bound JPEG frame size before copying into the buffer s2255_fillbuff() memcpy()s vc->jpg_size bytes of a captured JPEG/MJPEG frame into the vb2 plane. vc->jpg_size is taken verbatim from the S2255_MARKER_FRAME header the device sends (pdword[4] in save_frame()) and, unlike the frame payload length just above it, is never bounded: payload = le32_to_cpu(pdword[3]); if (payload > vc->req_image_size) /* payload is checked ... */ return -EINVAL; vc->pkt_size = payload; vc->jpg_size = le32_to_cpu(pdword[4]); /* ... jpg_size is not */ A malicious or malfunctioning device can therefore report a jpg_size larger than the destination vb2 plane, and the memcpy() writes past it. jpg_size is a signed int, so a value with the top bit set also turns into a huge length. Reject a frame whose jpg_size is negative or exceeds the plane size before copying it.

Affected products

Linux
  • =<7.2.*
  • <79f58f900dd221ab04ea74bf4eaf79fa3b0fcc77
  • =<6.1.*
  • ==2.6.27
  • =<6.12.*
  • <4b6f7bccc6559ae5c54573c284fe76eafc9989b2
  • <68d664f1b4efe525e99154b7058fcb0378bdaff7
  • =<5.15.*
  • =<6.18.*
  • =<*
  • <d2ecaaab6a4f165abb54cdf61be60030b5782bf8
  • <e504cc888f42999dd76b6a43788c422610f2aad2
  • <32a595dd3e8634544e5cfbc47f906dff3d3c1ef8
  • <2542516a147bfad740e7e411c251b639fad260ff
  • <dd739517560c8d0ec4463a53e717bf40b988d7da
  • <2.6.27
  • =<6.6.*
  • =<5.10.*
Dismissed
(no matching packages found)
Permalink CVE-2026-92565
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 3 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Rallly before 4.15.0 Information Disclosure via polls.get

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.

Affected products

rallly
  • ==4.15.0
  • <4.15.0