We’ve disclosed3402vulnerabilities
by Snyk Security
Researchers
Upgrade postgresql
to version 13.19, 14.16, 15.11, 16.7, 17.3 or higher.
generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page
Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the entityType
and qualifiedName
parameters in REST endpoints. An attacker can execute arbitrary code by passing malicious class names that lead to unintended class loading.
Note:
This is only exploitable if the attacker manages to place some malicious classes into the classpath and also has access to these REST interface for calling the mentioned REST endpoints.
xgrammar is an Efficient, Flexible and Portable Structured Generation
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in thread_safe_cache.h
, which can be populated by an indefinitely large number of entries corresponding to each new schema encountered. A user can exhaust all available memory on the system running the target application.
Note: A common use case for this caching is vLLM's guided encoding functionality.
Affected versions of this package are vulnerable to Incorrect Default Permissions. An attacker could achieve remote code execution and compromise MySQL Connectors by exploiting this vulnerability.
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.