Skip to content

トピトピニュース

Header Image
Archive

Month: December 2018

3 Posts

Featured

Posted byGitHub
[org.exist-db:exist-core] exist-db:exist-core XML External Entity (XXE) vulnerability
Posted byGitHub
[org.springframework.security:spring-security-oauth2-jose] Spring Security vulnerable to Authorization Bypass
Posted byGitHub
[org.springframework.security:spring-security-oauth2-jose] Spring Security vulnerable to Authorization Bypass

[org.exist-db:exist-core] exist-db:exist-core XML External Entity (XXE) vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 12/21/201811/16/2022

exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
References

https://nvd.nist.gov/vuln/detail/CVE-…

[org.springframework.security:spring-security-oauth2-jose] Spring Security vulnerable to Authorization Bypass

  • Posted inHIGH
  • Posted byGitHub
  • 12/21/201811/18/2022

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that ca…

[org.springframework.security:spring-security-oauth2-jose] Spring Security vulnerable to Authorization Bypass

  • Posted inHIGH
  • Posted byGitHub
  • 12/21/201811/18/2022

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that ca…

トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close