rpm package
suse/susemanager-tftpsync-recv&distro=SUSE Manager Proxy Module 4.2
pkg:rpm/suse/susemanager-tftpsync-recv&distro=SUSE%20Manager%20Proxy%20Module%204.2
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-31129 | — | < 4.2.5-150300.3.6.2 | 4.2.5-150300.3.6.2 | Jul 6, 2022 | moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried | ||
| CVE-2021-41411 | — | < 4.2.5-150300.3.6.2 | 4.2.5-150300.3.6.2 | Jun 16, 2022 | drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability. | ||
| CVE-2021-43138 | — | < 4.2.5-150300.3.6.2 | 4.2.5-150300.3.6.2 | Apr 6, 2022 | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution. | ||
| CVE-2021-42740 | — | < 4.2.5-150300.3.6.2 | 4.2.5-150300.3.6.2 | Oct 21, 2021 | The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command wi |
- CVE-2022-31129Jul 6, 2022affected < 4.2.5-150300.3.6.2fixed 4.2.5-150300.3.6.2
moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried
- CVE-2021-41411Jun 16, 2022affected < 4.2.5-150300.3.6.2fixed 4.2.5-150300.3.6.2
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
- CVE-2021-43138Apr 6, 2022affected < 4.2.5-150300.3.6.2fixed 4.2.5-150300.3.6.2
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
- CVE-2021-42740Oct 21, 2021affected < 4.2.5-150300.3.6.2fixed 4.2.5-150300.3.6.2
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command wi