Jonatan Männchen
15 exploits
Active since Oct 2021
ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks
CVSS 6.5
httpc leaks Authorization header to cross-origin redirect targets
CVSS 6.5
ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks
CVSS 6.5
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVSS 3.2
oidcc 3.0.0-3.0.1, 3.1.0-3.1.1, 3.2.0-beta.1-3.2.0-beta.2 - Denial of Service via Atom Exhaustion
CVSS 5.3
oidcc 3.0.0-3.0.1, 3.1.0-3.1.1, 3.2.0-beta.1-3.2.0-beta.2 - Denial of Service via Atom Exhaustion
CVSS 5.3
Lockfile checksums not verified in Hex allows dependency integrity bypass
CVSS 5.9
hexpm hexpm/hexpm - Privilege Escalation
CVSS 5.3
hexpm - Insufficient Session Expiration in Password Reset Token
CVSS 9.8
hex_core < 0.12.1, hex < 2.3.2, rebar3 < 3.27.0 - Resource Consumption & Untrusted Data Deserialization
CVSS 7.5
hexpm - Path Traversal in Elixir.Hexpm.Store.Local Module
CVSS 7.5
Hygeia 1.11.0-1.30.3 - CSV Injection in Statistics and BAG MED Exports
CVSS 9.1
oidcc 3.0.0-3.0.1, 3.1.0-3.1.1, 3.2.0-beta.1-3.2.0-beta.2 - Denial of Service via Atom Exhaustion
CVSS 5.3
ash < 3.6.2 - Authentication Bypass via Incorrect Authorization in Authorizer
hexpm - Cross-Site Scripting in SharedAuthorizationView render_grouped_scopes
CVSS 6.1