rpm package
opensuse/agama-web-ui&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Tumbleweed
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-13311 | Hig | 7.5 | < 23+75.1a877fb50-50.1 | 23+75.1a877fb50-50.1 | Jun 25, 2026 | shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacke | |
| CVE-2026-53663 | Low | 3.1 | < 23+0.f26ed5eab-49.1 | 23+0.f26ed5eab-49.1 | Jun 22, 2026 | React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections | |
| CVE-2026-34077 | Hig | 7.5 | < 22+143.ee15dea20-46.1 | 22+143.ee15dea20-46.1 | Jun 2, 2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sou | |
| CVE-2026-9277 | Hig | 8.1 | < 21+360.16caae772-44.1 | 21+360.16caae772-44.1 | May 22, 2026 | shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line te | |
| CVE-2026-6402 | Med | 5.3 | < 21+360.16caae772-44.1 | 21+360.16caae772-44.1 | May 12, 2026 | webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers om | |
| CVE-2023-28154 | Cri | 9.8 | < 9+52-1.1 | 9+52-1.1 | Mar 13, 2023 | Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object. |
- affected < 23+75.1a877fb50-50.1fixed 23+75.1a877fb50-50.1
shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacke
- affected < 23+0.f26ed5eab-49.1fixed 23+0.f26ed5eab-49.1
React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections
- affected < 22+143.ee15dea20-46.1fixed 22+143.ee15dea20-46.1
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sou
- affected < 21+360.16caae772-44.1fixed 21+360.16caae772-44.1
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line te
- affected < 21+360.16caae772-44.1fixed 21+360.16caae772-44.1
webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers om
- affected < 9+52-1.1fixed 9+52-1.1
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.