GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
147 advisories
Filter by severity
ydb-go-sdk token in custom credentials object can leak through logs
Moderate
CVE-2023-45825
was published
for
github.com/ydb-platform/ydb-go-sdk/v3
(Go)
Oct 19, 2023
Wagtail vulnerable to disclosure of user names via admin bulk action views
Low
CVE-2023-45809
was published
for
wagtail
(pip)
Oct 19, 2023
Argo CD cluster secret might leak in cluster details page
Critical
CVE-2023-40029
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 11, 2023
Improper masking of credentials in Jenkins Pipeline Maven Integration Plugin
Moderate
CVE-2023-41934
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
Sep 6, 2023
MongoDB Driver may publish events containing authentication-related data
Moderate
CVE-2021-32050
was published
for
github.com/mongodb/mongo-swift-driver
(Composer)
Aug 29, 2023
Improper log output when using GitHub Status Notifications in spinnaker
Moderate
CVE-2023-39348
was published
for
github.com/spinnaker/spinnaker
(Go)
Aug 29, 2023
Jenkins Folders Plugin information disclosure vulnerability
Moderate
CVE-2023-40338
was published
for
org.jenkins-ci.plugins:cloudbees-folder
(Maven)
Aug 16, 2023
Mattermost fails to sanitize post metadata
Moderate
CVE-2023-4108
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Aug 11, 2023
Weave GitOps Terraform Controller Information Disclosure Vulnerability
High
CVE-2023-34236
was published
for
github.com/weaveworks/tf-controller
(Go)
Jul 14, 2023
secrets-store-csi-driver discloses service account tokens in logs
Moderate
CVE-2023-2878
was published
for
sigs.k8s.io/secrets-store-csi-driver
(Go)
May 26, 2023
Jenkins HashiCorp Vault Plugin has improper masking of credentials
Moderate
CVE-2023-33001
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
May 16, 2023
@mittwald/kubernetes's secret contents leaked via debug logging
Moderate
GHSA-g35x-j6jj-8g7j
was published
for
@mittwald/kubernetes
(npm)
May 2, 2023
Lightbend Alpakka Kafka logs credentials on debug level
Moderate
CVE-2023-29471
was published
for
com.typesafe.akka:akka-stream-kafka
(Maven)
Apr 27, 2023
AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sending
Moderate
CVE-2023-30610
was published
for
aws-sigv4
(Rust)
Apr 26, 2023
Sensitive Terraform Output Values Printed At Info Logging Level In Kitchen-Terraform
Low
CVE-2023-30618
was published
for
kitchen-terraform
(RubyGems)
Apr 24, 2023
Debug mode leaks confidential data in Cilium
High
CVE-2023-29002
was published
for
github.com/cilium/cilium
(Go)
Apr 19, 2023
Veracode Scan Jenkins Plugin vulnerable to information disclosure
Moderate
CVE-2023-25721
was published
for
com.veracode.jenkins:veracode-scan
(Maven)
Mar 28, 2023
OpenShift Assisted Installer leaks image pull secrets as plaintext in installation logs
Moderate
CVE-2021-3684
was published
for
github.com/openshift/assisted-installer
(Go)
Mar 24, 2023
Spring Vault vulnerable to insertion of sensitive information into a log file
Moderate
CVE-2023-20859
was published
for
org.springframework.vault:spring-vault-core
(Maven)
Mar 23, 2023
directus vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2023-28443
was published
for
directus
(npm)
Mar 23, 2023
OpenNMS has potential Insertion of Sensitive Information into Log File vulnerability
Moderate
CVE-2023-0815
was published
for
org.opennms:opennms
(Maven)
Feb 23, 2023
Argo CD leaks repository credentials in user-facing error messages and in logs
Moderate
CVE-2023-25163
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Feb 8, 2023
Credential disclosure in syft when SYFT_ATTEST_PASSWORD environment variable set
Moderate
CVE-2023-24827
was published
for
github.com/anchore/syft
(Go)
Feb 8, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
Moderate
CVE-2020-8565
was published
for
k8s.io/client-go
(Go)
Feb 6, 2023
Kubernetes Sensitive Information leak via Log File
Moderate
CVE-2020-8564
was published
for
github.com/kubernetes/kubernetes
(Go)
Feb 6, 2023
ProTip!
Advisories are also available from the
GraphQL API