Search CVE reports
1921 – 1930 of 47976 results
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as...
1 affected package
simplesamlphp
| Package | 20.04 LTS |
|---|---|
| simplesamlphp | Needs evaluation |
SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path and find_base_path() removes the brackets, leaving a host...
1 affected package
sshfs-fuse
| Package | 20.04 LTS |
|---|---|
| sshfs-fuse | Needs evaluation |
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes...
1 affected package
sshfs-fuse
| Package | 20.04 LTS |
|---|---|
| sshfs-fuse | Needs evaluation |
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read...
1 affected package
python-git
| Package | 20.04 LTS |
|---|---|
| python-git | Needs evaluation |
nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside an extracted archive whose name contains a single quote followed by shell syntax. If...
1 affected package
nnn
| Package | 20.04 LTS |
|---|---|
| nnn | Needs evaluation |