
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Permissive List of Allowed Inputs
@backstage/plugin-techdocs-node is a Common node.js functionalities for TechDocs, to be shared between techdocs-backend plugin and techdocs-cli
Affected versions of this package are vulnerable to Permissive List of Allowed Inputs via the processing of the mkdocs.yml configuration file during the documentation build process. An attacker can execute arbitrary Python code by crafting a malicious configuration file that bypasses security controls through unfiltered configuration keys.
Improper Verification of Cryptographic Signature
authlib is a library in building OAuth and OpenID Connect servers.
Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in jwt.decode(), which accepts alg: none. An attacker can gain unauthorized access, escalate privileges, or modify application data by submitting a malicious JWT containing alg: none and an empty signature.
Improper Handling of Insufficient Permissions or Privileges
org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.
Affected versions of this package are vulnerable to Improper Handling of Insufficient Permissions or Privileges via improper enforcement of roles in the UMA 2.0 Protection API which fails to enforce the uma_protection role check. An attacker can access sensitive information by leveraging insufficient permission checks.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in mailparser (npm)- M
Incorrect Control Flow Scoping in @tootallnate/once (npm)- C
Arbitrary Code Injection in unisharp/laravel-filemanager (composer)- M
Infinite loop in bn.js (npm)- H
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in directorytree/imapengine (composer)
Snyk security
researchers
have disclosed
3469
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




