Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

201 advisories

Loading
Jenkins Git client Plugin file system information disclosure vulnerability Moderate
CVE-2025-58458 was published for org.jenkins-ci.plugins:git-client (Maven) Sep 3, 2025
Opencast still publishes global system account credentials Moderate
CVE-2025-54380 was published for org.opencastproject:opencast-common (Maven) Jul 25, 2025
lkiesow
OpenSearch unauthorized data access on fields protected by field level security if field is a member of an object Moderate
GHSA-2rjv-cv85-xhgm was published for org.opensearch.plugin:opensearch-security (Maven) Aug 1, 2025
OpenSearch unauthorized data access on fields protected by field masking for fields of type ip, geo_point, geo_shape, xy_point, xy_shape Moderate
GHSA-rrmm-wq7q-h4v5 was published for org.opensearch.plugin:opensearch-security (Maven) Aug 1, 2025
Reactor Netty HTTP is vulnerable to credential leaks during chained redirects Moderate
CVE-2025-22227 was published for io.projectreactor.netty:reactor-netty-http (Maven) Jul 16, 2025
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL Moderate
CVE-2022-42132 was published for com.liferay.portal:release.dxp.bom (Maven) Nov 15, 2022
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files Moderate
CVE-2025-26795 was published for org.apache.iotdb:iotdb-jdbc (Maven) May 14, 2025
AnonySE26
Generation of Error Message Containing Sensitive Information in Elasticsearch Moderate
CVE-2021-22145 was published for org.elasticsearch.client:elasticsearch-rest-client (Maven) May 24, 2022
Apache IoTDB Discloses Sensitive Information via Log Files Moderate
CVE-2025-26864 was published for apache-iotdb (Maven) May 14, 2025
Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling Moderate
CVE-2024-23944 was published for org.apache.zookeeper:zookeeper (Maven) Mar 15, 2024
GWC Home Page communicate version and revision information Moderate
CVE-2024-38524 was published for org.geoserver.web:gs-web-app (Maven) Jun 10, 2025
sikeoka
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password Moderate
CVE-2021-29043 was published for com.liferay.portal:release.dxp.bom (Maven) May 24, 2022
Liferay Portal and Liferay DXP Fails to Sanitize API Data Moderate
CVE-2020-13444 was published for com.liferay.portal:release.dxp.bom (Maven) May 24, 2022
Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens Moderate
CVE-2022-31684 was published for io.projectreactor.netty:reactor-netty-http (Maven) Oct 20, 2022
Apache Wicket allows attackers to check for third-party libraries Moderate
CVE-2014-0043 was published for org.apache.wicket:wicket-core (Maven) May 17, 2022
Apache Tomcat Mishandles Character Sequence in Cookies Moderate
CVE-2007-3385 was published for org.apache.tomcat:tomcat (Maven) May 1, 2022
Apache Tomcat Reveals Directories Moderate
CVE-2006-3835 was published for org.apache.tomcat:tomcat (Maven) May 1, 2022
Apache Tomcat Reveals Path through Long URL Moderate
CVE-2001-0917 was published for org.apache.tomcat:tomcat (Maven) Apr 30, 2022
Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor Moderate
CVE-2025-30474 was published for org.apache.commons:commons-vfs2 (Maven) Mar 23, 2025
Jenkins allows Remote Users to Obtain Sensitive Information from a Plugin Code Moderate
CVE-2014-3667 was published for org.jenkins-ci.main:jenkins-core (Maven) May 17, 2022
Jenkins Exposes Sensitive Information from Job Configuration Moderate
CVE-2016-3724 was published for org.jenkins-ci.main:jenkins-core (Maven) May 14, 2022
Jenkins Exposes Sensitive Information via API URL Moderate
CVE-2016-3727 was published for org.jenkins-ci.main:jenkins-core (Maven) May 14, 2022
Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor Moderate
CVE-2015-5320 was published for org.jenkins-ci.main:jenkins-core (Maven) May 13, 2022
Jenkins allows Unauthorized Viewing of Queue API Information Moderate
CVE-2015-5324 was published for org.jenkins-ci.main:jenkins-core (Maven) May 13, 2022
Jenkins has Information Disclosure via Sidepanel Widget Moderate
CVE-2015-5321 was published for org.jenkins-ci.main:jenkins-core (Maven) May 13, 2022
ProTip! Advisories are also available from the GraphQL API