VYPR

apk package

chainguard/opensearch-dashboards-2-dashboards-notifications

pkg:apk/chainguard/opensearch-dashboards-2-dashboards-notifications

Vulnerabilities (53)

  • CVE-2024-45801Sep 16, 2024
    affected < 2.19.1-r3fixed 2.19.1-r3

    DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollut

  • CVE-2024-45296HigSep 9, 2024
    affected < 2.19.1-r3fixed 2.19.1-r3

    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will

  • CVE-2024-39001Jul 1, 2024
    affected < 2.16.0-r0fixed 2.16.0-r0

    ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38996Jul 1, 2024
    affected < 2.16.0-r0fixed 2.16.0-r0

    ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-37890HigJun 17, 2024
    affected < 2.15.0-r1fixed 2.15.0-r1

    ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in ws@8.17.1 (e55e510) and backported to ws@7.5.10 (22c2876), ws@6.2.3 (e

  • CVE-2024-4068May 13, 2024
    affected < 2.15.0-r0fixed 2.15.0-r0

    The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program

  • CVE-2024-4067May 13, 2024
    affected < 2.19.1-r3fixed 2.19.1-r3

    The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching w

  • CVE-2024-28863Mar 21, 2024
    affected < 2.15.0-r0fixed 2.15.0-r0

    node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js cl

  • CVE-2024-28849Mar 14, 2024
    affected < 2.13.0-r0fixed 2.13.0-r0

    follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which

  • CVE-2023-26159Jan 2, 2024
    affected < 2.11.1-r2fixed 2.11.1-r2

    Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this

  • CVE-2023-45857Nov 8, 2023
    affected < 2.11.1-r2fixed 2.11.1-r2

    An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

  • CVE-2023-28155Mar 16, 2023
    affected < 2.19.1-r0fixed 2.19.1-r0

    The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintaine

  • CVE-2020-36604Sep 23, 2022
    affected < 2.11.1-r2fixed 2.11.1-r2

    hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.

Page 3 of 3