Nicolargo

Glances

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 17.08.2026 17:16:40
  • Zuletzt bearbeitet 18.08.2026 15:17:00

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wil...

  • EPSS 0.13%
  • Veröffentlicht 17.08.2026 17:10:25
  • Zuletzt bearbeitet 17.08.2026 18:18:06

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell operators enabled, allowing c...

  • EPSS 0.14%
  • Veröffentlicht 17.08.2026 17:07:49
  • Zuletzt bearbeitet 17.08.2026 19:16:33

Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to survive chev...

  • EPSS 0.24%
  • Veröffentlicht 17.08.2026 17:06:06
  • Zuletzt bearbeitet 17.08.2026 20:16:45

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthenticated GET /api...

  • EPSS 0.14%
  • Veröffentlicht 17.08.2026 16:18:29
  • Zuletzt bearbeitet 17.08.2026 20:16:45

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstru...

  • EPSS 0.23%
  • Veröffentlicht 25.06.2026 18:05:48
  • Zuletzt bearbeitet 26.06.2026 19:16:40

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE-2026-33533. However, the implementation silen...

  • EPSS 0.13%
  • Veröffentlicht 25.06.2026 18:04:25
  • Zuletzt bearbeitet 25.06.2026 19:58:30

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CAC...

  • EPSS 0.14%
  • Veröffentlicht 25.06.2026 18:03:43
  • Zuletzt bearbeitet 25.06.2026 19:58:30

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operato...

  • EPSS 0.14%
  • Veröffentlicht 25.06.2026 18:02:14
  • Zuletzt bearbeitet 25.06.2026 19:58:30

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/virsh.py) passes VM domain names, read directly from virsh list --all output, into f-string command t...

  • EPSS 0.12%
  • Veröffentlicht 25.06.2026 18:00:47
  • Zuletzt bearbeitet 26.06.2026 04:17:43

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTTP Host header, leaving it vulnerable to DNS rebinding attacks. An atta...