Skip to content

トピトピニュース

Header Image
Archive

Month: October 2018

6 Posts

Featured

Posted byGitHub
[org.eclipse.jetty:jetty-server] Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)
Posted byGitHub
[org.apache.struts:struts2-core] Apache Struts vulnerable to remote command execution (RCE) due to improper input validation
Posted byGitHub
[org.springframework:spring-core] Files or Directories Accessible to External Parties in org.springframework:spring-core
Posted byGitHub
[org.springframework:spring-core] Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass

[org.eclipse.jetty:jetty-server] Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/20/201810/06/2022

Eclipse Jetty Server versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), are vulnerable to HTTP Request Smuggling when presented with two content-lengths headers, allowing authorization bypass. Wh…

[org.apache.struts:struts2-core] Apache Struts vulnerable to remote command execution (RCE) due to improper input validation

  • Posted inHIGH
  • Posted byGitHub
  • 10/19/201810/05/2022

Apache Struts contains a Remote Code Execution when using results with no namespace and it’s upper actions have no or wildcard namespace. The same flaw exists when using a url tag with no value, action set, and it’s upper actions have no or wildcard n…

[org.springframework:spring-core] Files or Directories Accessible to External Parties in org.springframework:spring-core

  • Posted inHIGH
  • Posted byGitHub
  • 10/18/201810/05/2022

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script …

[org.springframework:spring-core] Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass

  • Posted inHIGH
  • Posted byGitHub
  • 10/18/201811/18/2022

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
…

[org.springframework:spring-core] Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass

  • Posted inHIGH
  • Posted byGitHub
  • 10/18/201811/18/2022

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
…

[Microsoft.AspNetCore.DataProtection.AzureStorage] Denial of service in ASP.NET Core

  • Posted inHIGH
  • Posted byGitHub
  • 10/17/201809/03/2022

A denial of service vulnerability exists when OData Library improperly handles web requests, aka “OData Denial of Service Vulnerability.” This affects Microsoft.Data.OData.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-8269
https://github.com/a…

トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close