Skip to content

トピトピニュース

Header Image
Archive

Month: October 2019

2 Posts

Featured

Posted byGitHub
[mongoose] Improper Input Validation in Automattic Mongoose
Posted byGitHub
[netaddr] netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions

[mongoose] Improper Input Validation in Automattic Mongoose

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/23/201910/21/2022

Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding “_bsontype”:”a” can sometimes interfere with a query filter. NOTE: th…

[netaddr] netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/15/201907/22/2022

The netaddr gem before 1.5.3 and 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-17383
https://github.com/dspinhir…

トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close