VYPR

rpm package

suse/subscription-matcher&distro=SUSE Manager Server Module 4.2

pkg:rpm/suse/subscription-matcher&distro=SUSE%20Manager%20Server%20Module%204.2

Vulnerabilities (9)

  • CVE-2022-31129Jul 6, 2022
    affected < 0.29-150300.6.12.2fixed 0.29-150300.6.12.2

    moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried

  • CVE-2022-31248Jun 22, 2022
    affected < 0.29-150300.6.9.2fixed 0.29-150300.6.9.2

    A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46-1. SUSE Manager Server 4.

  • CVE-2021-41411Jun 16, 2022
    affected < 0.29-150300.6.12.2fixed 0.29-150300.6.12.2

    drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.

  • CVE-2021-43138Apr 6, 2022
    affected < 0.29-150300.6.12.2fixed 0.29-150300.6.12.2

    In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.

  • CVE-2021-40348Nov 1, 2021
    affected < 0.27-6.3.1fixed 0.27-6.3.1

    Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to

  • CVE-2021-42740Oct 21, 2021
    affected < 0.29-150300.6.12.2fixed 0.29-150300.6.12.2

    The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command wi

  • CVE-2021-21996Sep 8, 2021
    affected < 0.27-6.3.1fixed 0.27-6.3.1

    An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

  • CVE-2019-5427Apr 22, 2019
    affected < 0.29-150300.6.6.1fixed 0.29-150300.6.6.1

    c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

  • CVE-2018-20433Dec 24, 2018
    affected < 0.29-150300.6.6.1fixed 0.29-150300.6.6.1

    c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.