Search CVE reports
1641 – 1650 of 46017 results
Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach...
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator,...
1 affected package
cryptojs
| Package | 20.04 LTS |
|---|---|
| cryptojs | Needs evaluation |
Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into...
1 affected package
ruby-json
| Package | 20.04 LTS |
|---|---|
| ruby-json | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as...
1 affected package
libimager-perl
| Package | 20.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |