rpm package
opensuse/python-Glances&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/python-Glances&distro=openSUSE%20Tumbleweed
Vulnerabilities (24)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-32609 | Hig | 7.5 | < 4.5.2-1.1 | 4.5.2-1.1 | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenticated configuration secrets exposure on the `/api/v4/config` endpoints by introducing `as_dict_secure()` redaction. However, the `/api/v4/args` and `/api/v4/arg | |
| CVE-2026-32608 | Hig | 7.0 | < 4.5.2-1.1 | 4.5.2-1.1 | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that execute when monitoring thresholds are exceeded. These commands support Mustache template variables (e.g., `{{name}}`, `{{key}}`) that | |
| CVE-2026-32596 | Hig | 7.5 | < 4.5.2-1.1 | 4.5.2-1.1 | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system information including process command-lines containing credentials (p | |
| CVE-2021-23418 | Med | 6.3 | < 4.5.6-1.1 | 4.5.6-1.1 | Jul 29, 2021 | The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks. |
- affected < 4.5.2-1.1fixed 4.5.2-1.1
Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenticated configuration secrets exposure on the `/api/v4/config` endpoints by introducing `as_dict_secure()` redaction. However, the `/api/v4/args` and `/api/v4/arg
- affected < 4.5.2-1.1fixed 4.5.2-1.1
Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that execute when monitoring thresholds are exceeded. These commands support Mustache template variables (e.g., `{{name}}`, `{{key}}`) that
- affected < 4.5.2-1.1fixed 4.5.2-1.1
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system information including process command-lines containing credentials (p
- affected < 4.5.6-1.1fixed 4.5.6-1.1
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
Page 2 of 2