CVE-2024-42346
- EPSS 10.3%
- Veröffentlicht 20.09.2024 19:15:15
- Zuletzt bearbeitet 15.08.2025 14:19:48
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger ...
CVE-2024-42351
- EPSS 0.38%
- Veröffentlicht 20.09.2024 19:15:15
- Zuletzt bearbeitet 15.08.2025 14:17:54
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or t...
CVE-2023-42812
- EPSS 0.08%
- Veröffentlicht 22.09.2023 17:15:14
- Zuletzt bearbeitet 21.11.2024 08:23:15
Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and r...
CVE-2023-27578
- EPSS 0.18%
- Veröffentlicht 20.03.2023 20:15:52
- Zuletzt bearbeitet 21.11.2024 07:53:11
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functiona...
CVE-2015-10062
- EPSS 1.4%
- Veröffentlicht 17.01.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 02:24:17
A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The manipulation leads to injection. Upgrading to version 14.10.1 is able to a...
CVE-2022-23470
- EPSS 0.41%
- Veröffentlicht 06.12.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:37
Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is runnin...
CVE-2018-1000516
- EPSS 0.5%
- Veröffentlicht 26.06.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:05
The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow for cross-site...