{"cves":[{"id":"CVE-2022-4843","published":"2022-12-29T18:15:00","updated_at":"2025-07-11T07:53:39.621843+00:00","description":"\nNULL Pointer Dereference in GitHub repository radareorg/radare2 prior to\n5.8.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://huntr.dev/bounties/075b2760-66a0-4d38-b3b5-e9934956ab7f","https://github.com/radareorg/radare2/commit/842f809d4ec6a12af2906f948657281c9ebc8a24","https://www.cve.org/CVERecord?id=CVE-2022-4843"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-25052","published":"2022-12-28T12:15:00","updated_at":"2025-08-26T12:08:49.575995+00:00","description":"\nA vulnerability has been found in Catalyst-Plugin-Session up to 0.40 and\nclassified as problematic. This vulnerability affects the function\n_load_sessionid of the file lib/Catalyst/Plugin/Session.pm of the component\nSession ID Handler. The manipulation of the argument sid leads to cross\nsite scripting. The attack can be initiated remotely. Upgrading to version\n0.41 is able to address this issue. The name of the patch is\n88d1b599e1163761c9bd53bec53ba078f13e09d4. It is recommended to upgrade the\naffected component. VDB-216958 is the identifier assigned to this\nvulnerability.","ubuntu_description":"","notes":[{"author":"eslerm","note":"CVE possibly assigned based on five year old commit message"}],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/perl-catalyst/Catalyst-Plugin-Session/releases/tag/0.41","https://www.cve.org/CVERecord?id=CVE-2018-25052"],"bugs":[""],"patches":{"libcatalyst-plugin-session-perl":["upstream: https://github.com/perl-catalyst/Catalyst-Plugin-Session/commit/88d1b599e1163761c9bd53bec53ba078f13e09d4"]},"tags":{},"packages":[{"name":"libcatalyst-plugin-session-perl","source":"https://ubuntu.com/security/cve?package=libcatalyst-plugin-session-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libcatalyst-plugin-session-perl","debian":"https://tracker.debian.org/pkg/libcatalyst-plugin-session-perl","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.41-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.41-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-25050","published":"2022-12-28T10:15:00","updated_at":"2025-07-11T07:41:06.653455+00:00","description":"\nA vulnerability, which was classified as problematic, has been found in\nHarvest Chosen up to 1.8.6. Affected by this issue is the function\nAbstractChosen of the file coffee/lib/abstract-chosen.coffee. The\nmanipulation of the argument group_label leads to cross site scripting. The\nattack may be launched remotely. Upgrading to version 1.8.7 is able to\naddress this issue. The name of the patch is\n77fd031d541e77510268d1041ed37798fdd1017e. It is recommended to upgrade the\naffected component. The identifier of this vulnerability is VDB-216956.","ubuntu_description":"","notes":[{"author":"eslerm","note":"CVE possibly assigned based on four year old commit message"}],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/harvesthq/chosen/releases/tag/v1.8.7","https://github.com/harvesthq/chosen/pull/2997","https://www.cve.org/CVERecord?id=CVE-2018-25050"],"bugs":[""],"patches":{"libjs-chosen":["upstream: https://github.com/harvesthq/chosen/commit/77fd031d541e77510268d1041ed37798fdd1017e"]},"tags":{},"packages":[{"name":"libjs-chosen","source":"https://ubuntu.com/security/cve?package=libjs-chosen","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libjs-chosen","debian":"https://tracker.debian.org/pkg/libjs-chosen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-41966","published":"2022-12-28T00:15:00","updated_at":"2025-07-11T07:52:48.852423+00:00","description":"\nXStream serializes Java objects to XML and back again. Versions prior to\n1.4.20 may allow a remote attacker to terminate the application with a\nstack overflow error, resulting in a denial of service only via\nmanipulation the processed input stream. The attack uses the hash code\nimplementation for collections and maps to force recursive hash calculation\ncausing a stack overflow. This issue is patched in version 1.4.20 which\nhandles the stack overflow and raises an InputManipulationException\ninstead. A potential workaround for users who only use HashMap or HashSet\nand whose XML refers these only as default map or set, is to change the\ndefault implementation of java.util.Map and java.util per the code example\nin the referenced advisory. However, this implies that your application\ndoes not care about the implementation of the map and all elements are\ncomparable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-j563-grx4-pjpv","https://x-stream.github.io/CVE-2022-41966.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2022-41966"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1027754"],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.4.18-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1.4.19-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.4.7-1ubuntu0.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"1.4.8-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2022-3064","published":"2022-12-27T22:15:00","updated_at":"2025-06-24T14:57:40.163687+00:00","description":"\nParsing malicious or large YAML documents can consume excessive amounts of\nCPU or memory.","ubuntu_description":"","notes":[{"author":"leosilva","note":"kubernates is in fact a kubernetes installer\nthat calls snap, not the package it self."},{"author":"allenpthuang","note":"golang-github-coreos-discovery-etcd-io is potentially\naffected due to vendored go-yaml in vendor/gopkg.in/yaml.v2"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/go-yaml/yaml/releases/tag/v2.2.4","https://pkg.go.dev/vuln/GO-2022-0956","https://github.com/go-yaml/yaml/commit/f221b8435cfb71e54062f6c6e99e9ade30b124d5","https://ubuntu.com/security/notices/USN-6287-1","https://www.cve.org/CVERecord?id=CVE-2022-3064"],"bugs":[""],"patches":{"golang-github-coreos-discovery-etcd-io":[],"golang-gopkg-yaml.v3":[],"golang-yaml.v2":[],"kubernetes":[],"singularity-container":[],"webhook":[]},"tags":{},"packages":[{"name":"golang-github-coreos-discovery-etcd-io","source":"https://ubuntu.com/security/cve?package=golang-github-coreos-discovery-etcd-io","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-coreos-discovery-etcd-io","debian":"https://tracker.debian.org/pkg/golang-github-coreos-discovery-etcd-io","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]},{"name":"golang-gopkg-yaml.v3","source":"https://ubuntu.com/security/cve?package=golang-gopkg-yaml.v3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-gopkg-yaml.v3","debian":"https://tracker.debian.org/pkg/golang-gopkg-yaml.v3","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.2.4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.2.4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.2.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.2.4","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.2.4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.2.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.2.4","component":null,"pocket":"security"}]},{"name":"kubernetes","source":"https://ubuntu.com/security/cve?package=kubernetes","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kubernetes","debian":"https://tracker.debian.org/pkg/kubernetes","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"singularity-container","source":"https://ubuntu.com/security/cve?package=singularity-container","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=singularity-container","debian":"https://tracker.debian.org/pkg/singularity-container","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webhook","source":"https://ubuntu.com/security/cve?package=webhook","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webhook","debian":"https://tracker.debian.org/pkg/webhook","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"golang-yaml.v2","source":"https://ubuntu.com/security/cve?package=golang-yaml.v2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-yaml.v2","debian":"https://tracker.debian.org/pkg/golang-yaml.v2","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.0+git20170407.0.cd8b52f-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.2.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.0+git20160301.0.a83829b-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6287-1"],"notices":[{"id":"USN-6287-1","title":"Go yaml vulnerabilities","summary":"Several security issues were patched in the Go yaml package.\n","instructions":"After a standard system update anything that depends on golang-yaml.v2 needs\nto be rebuilt to make all the necessary changes.\n","references":[],"published":"2023-08-14T08:42:37.478149","description":"Simon Ferquel discovered that the Go yaml package incorrectly handled\ncertain YAML documents. If a user or an automated system were tricked\ninto opening a specially crafted input file, a remote attacker could\npossibly use this issue to cause the system to crash, resulting in\na denial of service. (CVE-2021-4235)\n\nIt was discovered that the Go yaml package incorrectly handled\ncertain large YAML documents. If a user or an automated system were tricked\ninto opening a specially crafted input file, a remote attacker could\npossibly use this issue to cause the system to crash, resulting in\na denial of service. (CVE-2022-3064)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"golang-yaml.v2","version":"0.0+git20170407.0.cd8b52f-1ubuntu2+esm1","description":"YAML support for the Go language","is_source":true},{"name":"golang-gopkg-yaml.v2-dev","version":"0.0+git20170407.0.cd8b52f-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":null,"pocket":"esm-apps"},{"name":"golang-yaml.v2-dev","version":"0.0+git20170407.0.cd8b52f-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"golang-yaml.v2","version":"2.2.2-1ubuntu0.1","description":"YAML support for the Go language","is_source":true},{"name":"golang-gopkg-yaml.v2-dev","version":"2.2.2-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2/2.2.2-1ubuntu0.1","pocket":"security"},{"name":"golang-yaml.v2-dev","version":"2.2.2-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2/2.2.2-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"golang-yaml.v2","version":"0.0+git20160301.0.a83829b-1ubuntu0.1~esm1","description":"YAML support for the Go language","is_source":true},{"name":"golang-yaml.v2-dev","version":"0.0+git20160301.0.a83829b-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-3064","CVE-2021-4235"]}]},{"id":"CVE-2022-2582","published":"2022-12-27T22:15:00","updated_at":"2025-08-26T12:43:44.890744+00:00","description":"\nThe AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside\nthe ciphertext as a metadata field. This hash can be used to brute force\nthe plaintext, if the hash is readable to the attacker. AWS now blocks this\nmetadata field, but older SDK versions still send it.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/aws/aws-sdk-go/commit/35fa6ddf45c061e0f08d3a3b5119f8f4da38f6d1 (v1.33.0)","https://github.com/aws/aws-sdk-go/commit/35fa6ddf45c061e0f08d3a3b5119f8f4da38f6d1","https://pkg.go.dev/vuln/GO-2022-0391","https://www.cve.org/CVERecord?id=CVE-2022-2582"],"bugs":[""],"patches":{"golang-github-aws-aws-sdk-go":[]},"tags":{},"packages":[{"name":"golang-github-aws-aws-sdk-go","source":"https://ubuntu.com/security/cve?package=golang-github-aws-aws-sdk-go","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-aws-aws-sdk-go","debian":"https://tracker.debian.org/pkg/golang-github-aws-aws-sdk-go","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.41.14-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.34.22-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-4239","published":"2022-12-27T22:15:00","updated_at":"2025-07-11T07:48:24.384908+00:00","description":"\nThe Noise protocol implementation suffers from weakened cryptographic\nsecurity after encrypting 2^64 messages, and a potential denial of service\nattack. After 2^64 (~18.4 quintillion) messages are encrypted with the\nEncrypt function, the nonce counter will wrap around, causing multiple\nmessages to be encrypted with the same key and nonce. In a separate issue,\nthe Decrypt function increments the nonce state even when it fails to\ndecrypt a message. If an attacker can provide an invalid input to the\nDecrypt function, this will cause the nonce state to desynchronize between\nthe peers, resulting in a failure to encrypt all subsequent messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/flynn/noise/pull/44","https://pkg.go.dev/vuln/GO-2022-0425","https://www.cve.org/CVERecord?id=CVE-2021-4239"],"bugs":[""],"patches":{"golang-github-flynn-noise":[]},"tags":{},"packages":[{"name":"golang-github-flynn-noise","source":"https://ubuntu.com/security/cve?package=golang-github-flynn-noise","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-flynn-noise","debian":"https://tracker.debian.org/pkg/golang-github-flynn-noise","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-4238","published":"2022-12-27T22:15:00","updated_at":"2025-07-11T07:48:24.384908+00:00","description":"\nRandomly-generated alphanumeric strings contain significantly less entropy\nthan expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric\nfunctions always return strings containing at least one digit from 0 to 9.\nThis significantly reduces the amount of entropy in short strings generated\nby these functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/Masterminds/goutils/commit/869801f20f9f1e7ecdbdb6422049d8241270d5e1","https://pkg.go.dev/vuln/GO-2022-0411","https://www.cve.org/CVERecord?id=CVE-2021-4238"],"bugs":[""],"patches":{"golang-github-masterminds-goutils":[]},"tags":{},"packages":[{"name":"golang-github-masterminds-goutils","source":"https://ubuntu.com/security/cve?package=golang-github-masterminds-goutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-masterminds-goutils","debian":"https://tracker.debian.org/pkg/golang-github-masterminds-goutils","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-4235","published":"2022-12-27T22:15:00","updated_at":"2025-06-24T14:53:19.802933+00:00","description":"\nDue to unbounded alias chasing, a maliciously crafted YAML file can cause\nthe system to consume significant system resources. If parsing user input,\nthis may be used as a denial of service vector.","ubuntu_description":"","notes":[{"author":"leosilva","note":"kubernates is in fact a kubernetes installer\nthat calls snap, not the package it self."},{"author":"allenpthuang","note":"golang-github-coreos-discovery-etcd-io is potentially\naffected due to vendored go-yaml in vendor/gopkg.in/yaml.v2"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/go-yaml/yaml/commit/bb4e33bf68bf89cad44d386192cbed201f35b241","https://pkg.go.dev/vuln/GO-2021-0061","https://github.com/go-yaml/yaml/pull/375","https://ubuntu.com/security/notices/USN-6287-1","https://www.cve.org/CVERecord?id=CVE-2021-4235"],"bugs":[""],"patches":{"golang-github-coreos-discovery-etcd-io":[],"golang-gopkg-yaml.v3":[],"golang-yaml.v2":[],"kubernetes":[],"singularity-container":[],"webhook":[]},"tags":{},"packages":[{"name":"golang-github-coreos-discovery-etcd-io","source":"https://ubuntu.com/security/cve?package=golang-github-coreos-discovery-etcd-io","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-coreos-discovery-etcd-io","debian":"https://tracker.debian.org/pkg/golang-github-coreos-discovery-etcd-io","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]},{"name":"golang-gopkg-yaml.v3","source":"https://ubuntu.com/security/cve?package=golang-gopkg-yaml.v3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-gopkg-yaml.v3","debian":"https://tracker.debian.org/pkg/golang-gopkg-yaml.v3","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.2.3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.2.3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.2.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.2.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.2.3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.2.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.2.3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.2.3","component":null,"pocket":"security"}]},{"name":"kubernetes","source":"https://ubuntu.com/security/cve?package=kubernetes","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kubernetes","debian":"https://tracker.debian.org/pkg/kubernetes","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"singularity-container","source":"https://ubuntu.com/security/cve?package=singularity-container","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=singularity-container","debian":"https://tracker.debian.org/pkg/singularity-container","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"webhook","source":"https://ubuntu.com/security/cve?package=webhook","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webhook","debian":"https://tracker.debian.org/pkg/webhook","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"golang-yaml.v2","source":"https://ubuntu.com/security/cve?package=golang-yaml.v2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-yaml.v2","debian":"https://tracker.debian.org/pkg/golang-yaml.v2","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.0+git20170407.0.cd8b52f-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.2.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.0+git20160301.0.a83829b-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"mantic","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.2.8-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6287-1"],"notices":[{"id":"USN-6287-1","title":"Go yaml vulnerabilities","summary":"Several security issues were patched in the Go yaml package.\n","instructions":"After a standard system update anything that depends on golang-yaml.v2 needs\nto be rebuilt to make all the necessary changes.\n","references":[],"published":"2023-08-14T08:42:37.478149","description":"Simon Ferquel discovered that the Go yaml package incorrectly handled\ncertain YAML documents. If a user or an automated system were tricked\ninto opening a specially crafted input file, a remote attacker could\npossibly use this issue to cause the system to crash, resulting in\na denial of service. (CVE-2021-4235)\n\nIt was discovered that the Go yaml package incorrectly handled\ncertain large YAML documents. If a user or an automated system were tricked\ninto opening a specially crafted input file, a remote attacker could\npossibly use this issue to cause the system to crash, resulting in\na denial of service. (CVE-2022-3064)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"golang-yaml.v2","version":"0.0+git20170407.0.cd8b52f-1ubuntu2+esm1","description":"YAML support for the Go language","is_source":true},{"name":"golang-gopkg-yaml.v2-dev","version":"0.0+git20170407.0.cd8b52f-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":null,"pocket":"esm-apps"},{"name":"golang-yaml.v2-dev","version":"0.0+git20170407.0.cd8b52f-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"golang-yaml.v2","version":"2.2.2-1ubuntu0.1","description":"YAML support for the Go language","is_source":true},{"name":"golang-gopkg-yaml.v2-dev","version":"2.2.2-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2/2.2.2-1ubuntu0.1","pocket":"security"},{"name":"golang-yaml.v2-dev","version":"2.2.2-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2/2.2.2-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"golang-yaml.v2","version":"0.0+git20160301.0.a83829b-1ubuntu0.1~esm1","description":"YAML support for the Go language","is_source":true},{"name":"golang-yaml.v2-dev","version":"0.0+git20160301.0.a83829b-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-yaml.v2","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-3064","CVE-2021-4235"]}]},{"id":"CVE-2020-36568","published":"2022-12-27T22:15:00","updated_at":"2025-07-11T07:45:38.404804+00:00","description":"\nUnsanitized input in the query parser in github.com/revel/revel before\nv1.0.0 allows remote attackers to cause resource exhaustion via memory\nallocation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/revel/revel/commit/d160ecb72207824005b19778594cbdc272e8a605","https://github.com/revel/revel/issues/1424","https://pkg.go.dev/vuln/GO-2020-0003","https://github.com/revel/revel/pull/1427","https://www.cve.org/CVERecord?id=CVE-2020-36568"],"bugs":[""],"patches":{"golang-github-revel-revel":[]},"tags":{},"packages":[{"name":"golang-github-revel-revel","source":"https://ubuntu.com/security/cve?package=golang-github-revel-revel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-revel-revel","debian":"https://tracker.debian.org/pkg/golang-github-revel-revel","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-25072","published":"2022-12-27T22:15:00","updated_at":"2026-02-09T07:17:16.313038+00:00","description":"\nDue to support of Gzip compression in request bodies, as well as a lack of\nlimiting response body sizes, a malicious server can cause a client to\nconsume a significant amount of system resources, which may be used as a\ndenial of service vector.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/tendermint/tendermint/commit/03085c2da23b179c4a51f59a03cb40aa4e85a613","https://pkg.go.dev/vuln/GO-2020-0037","https://github.com/tendermint/tendermint/pull/3430","https://www.cve.org/CVERecord?id=CVE-2019-25072"],"bugs":[""],"patches":{"tendermint":["upstream: https://github.com/tendermint/tendermint/commit/03085c2da23b179c4a51f59a03cb40aa4e85a613"]},"tags":{},"packages":[{"name":"tendermint","source":"https://ubuntu.com/security/cve?package=tendermint","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tendermint","debian":"https://tracker.debian.org/pkg/tendermint","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.38.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-20146","published":"2022-12-27T22:15:00","updated_at":"2025-06-24T14:48:45.057318+00:00","description":"\nUsage of the CORS handler may apply improper CORS headers, allowing the\nrequester to explicitly control the value of the\nAccess-Control-Allow-Origin header, which bypasses the expected behavior of\nthe Same Origin Policy.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/gorilla/handlers/commit/90663712d74cb411cbef281bc1e08c19d1a76145","https://github.com/gorilla/handlers/pull/116","https://pkg.go.dev/vuln/GO-2020-0020","https://www.cve.org/CVERecord?id=CVE-2017-20146"],"bugs":[""],"patches":{"golang-github-coreos-discovery-etcd-io":[],"golang-github-gorilla-handlers":[]},"tags":{},"packages":[{"name":"golang-github-coreos-discovery-etcd-io","source":"https://ubuntu.com/security/cve?package=golang-github-coreos-discovery-etcd-io","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-coreos-discovery-etcd-io","debian":"https://tracker.debian.org/pkg/golang-github-coreos-discovery-etcd-io","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"golang-github-gorilla-handlers","source":"https://ubuntu.com/security/cve?package=golang-github-gorilla-handlers","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-gorilla-handlers","debian":"https://tracker.debian.org/pkg/golang-github-gorilla-handlers","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-36567","published":"2022-12-27T21:15:00","updated_at":"2025-08-26T12:25:57.130395+00:00","description":"\nUnsanitized input in the default logger in github.com/gin-gonic/gin before\nv1.6.0 allows remote attackers to inject arbitrary log lines.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/gin-gonic/gin/pull/2237","https://github.com/gin-gonic/gin/commit/a71af9c144f9579f6dbe945341c1df37aaf09c0d (v1.6.0)","https://pkg.go.dev/vuln/GO-2020-0001","https://github.com/gin-gonic/gin/commit/a71af9c144f9579f6dbe945341c1df37aaf09c0d","https://www.cve.org/CVERecord?id=CVE-2020-36567"],"bugs":[""],"patches":{"golang-github-gin-gonic-gin":[]},"tags":{},"packages":[{"name":"golang-github-gin-gonic-gin","source":"https://ubuntu.com/security/cve?package=golang-github-gin-gonic-gin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-github-gin-gonic-gin","debian":"https://tracker.debian.org/pkg/golang-github-gin-gonic-gin","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.6.3-4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.3-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-4730","published":"2022-12-27T15:15:00","updated_at":"2025-07-11T07:53:39.621843+00:00","description":"\nA vulnerability was found in Graphite Web. It has been classified as\nproblematic. Affected is an unknown function of the component Absolute Time\nRange Handler. The manipulation leads to cross site scripting. It is\npossible to launch the attack remotely. The exploit has been disclosed to\nthe public and may be used. The name of the patch is\n2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a\npatch to fix this issue. The identifier of this vulnerability is\nVDB-216744.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/graphite-project/graphite-web/commit/2f178f490e10efc03cd1d27c72f64ecab224eb23","https://github.com/graphite-project/graphite-web/issues/2746","https://github.com/graphite-project/graphite-web/pull/2785","https://ubuntu.com/security/notices/USN-6243-1","https://www.cve.org/CVERecord?id=CVE-2022-4730"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1026992"],"patches":{"graphite-web":[]},"tags":{},"packages":[{"name":"graphite-web","source":"https://ubuntu.com/security/cve?package=graphite-web","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphite-web","debian":"https://tracker.debian.org/pkg/graphite-web","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2+debian-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.1.4-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.1.8-1ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.9.12+debian-3ubuntu0.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.9.15+debian-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.1.8-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6243-1"],"notices":[{"id":"USN-6243-1","title":"Graphite-Web vulnerabilities","summary":"Several security issues were fixed in Graphite-Web.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-07-25T08:34:41.592015","description":"It was discovered that Graphite-Web incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to perform\nserver-side request forgery and obtain sensitive information. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2017-18638)\n\nIt was discovered that Graphite-Web incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to perform \ncross site scripting and obtain sensitive information. (CVE-2022-4728,\nCVE-2022-4729, CVE-2022-4730)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"graphite-web","version":"0.9.15+debian-1ubuntu0.1~esm1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"0.9.15+debian-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"graphite-web","version":"1.1.8-1ubuntu0.22.04.1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.1.8-1ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":"https://launchpad.net/ubuntu/+source/graphite-web/1.1.8-1ubuntu0.22.04.1","pocket":"security"}],"focal":[{"name":"graphite-web","version":"1.1.4-5ubuntu0.1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.1.4-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":"https://launchpad.net/ubuntu/+source/graphite-web/1.1.4-5ubuntu0.1","pocket":"security"}],"bionic":[{"name":"graphite-web","version":"1.0.2+debian-2ubuntu0.1~esm1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.0.2+debian-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"graphite-web","version":"0.9.12+debian-3ubuntu0.1~esm2","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"0.9.12+debian-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-4730","CVE-2017-18638","CVE-2022-4728","CVE-2022-4729"]}]},{"id":"CVE-2022-4729","published":"2022-12-27T15:15:00","updated_at":"2025-07-11T07:53:37.663896+00:00","description":"\nA vulnerability was found in Graphite Web and classified as problematic.\nThis issue affects some unknown processing of the component Template Name\nHandler. The manipulation leads to cross site scripting. The attack may be\ninitiated remotely. The exploit has been disclosed to the public and may be\nused. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It\nis recommended to apply a patch to fix this issue. The associated\nidentifier of this vulnerability is VDB-216743.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/graphite-project/graphite-web/commit/2f178f490e10efc03cd1d27c72f64ecab224eb23","https://github.com/graphite-project/graphite-web/issues/2745","https://github.com/graphite-project/graphite-web/pull/2785","https://ubuntu.com/security/notices/USN-6243-1","https://www.cve.org/CVERecord?id=CVE-2022-4729"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1026992"],"patches":{"graphite-web":[]},"tags":{},"packages":[{"name":"graphite-web","source":"https://ubuntu.com/security/cve?package=graphite-web","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphite-web","debian":"https://tracker.debian.org/pkg/graphite-web","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2+debian-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.1.4-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.1.8-1ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.9.12+debian-3ubuntu0.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.9.15+debian-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.1.8-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-6243-1"],"notices":[{"id":"USN-6243-1","title":"Graphite-Web vulnerabilities","summary":"Several security issues were fixed in Graphite-Web.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-07-25T08:34:41.592015","description":"It was discovered that Graphite-Web incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to perform\nserver-side request forgery and obtain sensitive information. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2017-18638)\n\nIt was discovered that Graphite-Web incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to perform \ncross site scripting and obtain sensitive information. (CVE-2022-4728,\nCVE-2022-4729, CVE-2022-4730)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"graphite-web","version":"0.9.15+debian-1ubuntu0.1~esm1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"0.9.15+debian-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"graphite-web","version":"1.1.8-1ubuntu0.22.04.1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.1.8-1ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":"https://launchpad.net/ubuntu/+source/graphite-web/1.1.8-1ubuntu0.22.04.1","pocket":"security"}],"focal":[{"name":"graphite-web","version":"1.1.4-5ubuntu0.1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.1.4-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":"https://launchpad.net/ubuntu/+source/graphite-web/1.1.4-5ubuntu0.1","pocket":"security"}],"bionic":[{"name":"graphite-web","version":"1.0.2+debian-2ubuntu0.1~esm1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.0.2+debian-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"graphite-web","version":"0.9.12+debian-3ubuntu0.1~esm2","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"0.9.12+debian-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-4730","CVE-2017-18638","CVE-2022-4728","CVE-2022-4729"]}]},{"id":"CVE-2022-4728","published":"2022-12-27T15:15:00","updated_at":"2025-07-11T07:53:37.663896+00:00","description":"\nA vulnerability has been found in Graphite Web and classified as\nproblematic. This vulnerability affects unknown code of the component\nCookie Handler. The manipulation leads to cross site scripting. The attack\ncan be initiated remotely. The exploit has been disclosed to the public and\nmay be used. The name of the patch is\n2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a\npatch to fix this issue. VDB-216742 is the identifier assigned to this\nvulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/graphite-project/graphite-web/commit/2f178f490e10efc03cd1d27c72f64ecab224eb23","https://github.com/graphite-project/graphite-web/issues/2744","https://github.com/graphite-project/graphite-web/pull/2785","https://ubuntu.com/security/notices/USN-6243-1","https://www.cve.org/CVERecord?id=CVE-2022-4728"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1026992"],"patches":{"graphite-web":[]},"tags":{},"packages":[{"name":"graphite-web","source":"https://ubuntu.com/security/cve?package=graphite-web","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphite-web","debian":"https://tracker.debian.org/pkg/graphite-web","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2+debian-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.1.4-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.1.8-1ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.9.12+debian-3ubuntu0.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.9.15+debian-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.1.8-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6243-1"],"notices":[{"id":"USN-6243-1","title":"Graphite-Web vulnerabilities","summary":"Several security issues were fixed in Graphite-Web.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-07-25T08:34:41.592015","description":"It was discovered that Graphite-Web incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to perform\nserver-side request forgery and obtain sensitive information. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2017-18638)\n\nIt was discovered that Graphite-Web incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to perform \ncross site scripting and obtain sensitive information. (CVE-2022-4728,\nCVE-2022-4729, CVE-2022-4730)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"graphite-web","version":"0.9.15+debian-1ubuntu0.1~esm1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"0.9.15+debian-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"graphite-web","version":"1.1.8-1ubuntu0.22.04.1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.1.8-1ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":"https://launchpad.net/ubuntu/+source/graphite-web/1.1.8-1ubuntu0.22.04.1","pocket":"security"}],"focal":[{"name":"graphite-web","version":"1.1.4-5ubuntu0.1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.1.4-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":"https://launchpad.net/ubuntu/+source/graphite-web/1.1.4-5ubuntu0.1","pocket":"security"}],"bionic":[{"name":"graphite-web","version":"1.0.2+debian-2ubuntu0.1~esm1","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"1.0.2+debian-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"graphite-web","version":"0.9.12+debian-3ubuntu0.1~esm2","description":"A highly scalable real-time graphing system","is_source":true},{"name":"graphite-web","version":"0.9.12+debian-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphite-web","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-4730","CVE-2017-18638","CVE-2022-4728","CVE-2022-4729"]}]},{"id":"CVE-2021-4287","published":"2022-12-27T11:15:00","updated_at":"2025-08-26T12:35:53.534711+00:00","description":"\nA vulnerability, which was classified as problematic, was found in ReFirm\nLabs binwalk up to 2.3.2. Affected is an unknown function of the file\nsrc/binwalk/modules/extractor.py of the component Archive Extraction\nHandler. The manipulation leads to symlink following. It is possible to\nlaunch the attack remotely. Upgrading to version 2.3.3 is able to address\nthis issue. The name of the patch is\nfa0c0bd59b8588814756942fe4cb5452e76c1dcd. It is recommended to upgrade the\naffected component. The identifier of this vulnerability is VDB-216876.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/ReFirmLabs/binwalk/pull/556","https://github.com/ReFirmLabs/binwalk/releases/tag/v2.3.3","https://www.cve.org/CVERecord?id=CVE-2021-4287"],"bugs":[""],"patches":{"binwalk":["upstream: https://github.com/ReFirmLabs/binwalk/commit/fa0c0bd59b8588814756942fe4cb5452e76c1dcd"]},"tags":{},"packages":[{"name":"binwalk","source":"https://ubuntu.com/security/cve?package=binwalk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binwalk","debian":"https://tracker.debian.org/pkg/binwalk","statuses":[{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.3.3+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.3+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-4286","published":"2022-12-27T11:15:00","updated_at":"2025-07-11T07:48:26.469424+00:00","description":"\nA vulnerability, which was classified as problematic, has been found in\ncocagne pysrp up to 1.0.16. This issue affects the function calculate_x of\nthe file srp/_ctsrp.py. The manipulation leads to information exposure\nthrough discrepancy. Upgrading to version 1.0.17 is able to address this\nissue. The name of the patch is dba52642f5e95d3da7af1780561213ee6053195f.\nIt is recommended to upgrade the affected component. The associated\nidentifier of this vulnerability is VDB-216875.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"ADJACENT","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.6,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/cocagne/pysrp/releases/tag/1.0.17","https://github.com/cocagne/pysrp/pull/43","https://www.cve.org/CVERecord?id=CVE-2021-4286"],"bugs":[""],"patches":{"python-srp":["upstream: https://github.com/cocagne/pysrp/commit/dba52642f5e95d3da7af1780561213ee6053195f"]},"tags":{},"packages":[{"name":"python-srp","source":"https://ubuntu.com/security/cve?package=python-srp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python-srp","debian":"https://tracker.debian.org/pkg/python-srp","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-10005","published":"2022-12-27T09:15:00","updated_at":"2025-07-11T07:38:06.836985+00:00","description":"\nA vulnerability was found in markdown-it up to 2.x. It has been classified\nas problematic. Affected is an unknown function of the file\nlib/common/html_re.js. The manipulation leads to inefficient regular\nexpression complexity. Upgrading to version 3.0.0 is able to address this\nissue. The name of the patch is 89c8620157d6e38f9872811620d25138fc9d1b0d.\nIt is recommended to upgrade the affected component. The identifier of this\nvulnerability is VDB-216852.","ubuntu_description":"","notes":[{"author":"eslerm","note":"does not appear to be a vulnerability"}],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/markdown-it/markdown-it/releases/tag/3.0.0","https://www.cve.org/CVERecord?id=CVE-2015-10005"],"bugs":[""],"patches":{"node-markdown-it":["upstream: https://github.com/markdown-it/markdown-it/commit/89c8620157d6e38f9872811620d25138fc9d1b0d"]},"tags":{},"packages":[{"name":"node-markdown-it","source":"https://ubuntu.com/security/cve?package=node-markdown-it","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=node-markdown-it","debian":"https://tracker.debian.org/pkg/node-markdown-it","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-14802","published":"2022-12-26T21:15:00","updated_at":"2025-08-26T12:12:38.340369+00:00","description":"\nHashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended\nenvironment variables to the rendering task during template rendering, aka\nGHSA-6hv3-7c34-4hx8. This applies to\nnomad/client/allocrunner/taskrunner/template.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://advisories.gitlab.com/advisory/advgo_github_com_hashicorp_nomad_client_allocrunner_taskrunner_template_GMS_2022_818.html","https://www.hashicorp.com/blog/category/nomad","https://www.cve.org/CVERecord?id=CVE-2019-14802"],"bugs":[""],"patches":{"nomad":[]},"tags":{},"packages":[{"name":"nomad","source":"https://ubuntu.com/security/cve?package=nomad","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nomad","debian":"https://tracker.debian.org/pkg/nomad","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.6+dfsg1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":36100,"limit":20,"total_results":79316}