Skip to content

トピトピニュース

Header Image
Archive

Month: January 2022

38 Posts

Featured

Posted byUbergizmo Japan
GoogleのPixel Watchが5月に登場?
Posted byGitHub
[net.mingsoft:ms-mcms] Mingsoft MCMS vulnerable to Remote Code Execution via file upload.
Posted byFunglr Games(日本語)
Xtrfyの大人気肉抜きマウス「M4」に遂にワイヤレスモデルが登場!日本発売決定!
Posted byPRONEWS
Vol.170 「DJI Action 2」実機レビュー。自由な視点で撮影できるアクションカメラ登場[OnGoing Re:View]

[org.conjur.jenkins:conjur-credentials] Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows decrypting secrets

  • Posted inMODERATE
  • Posted byGitHub
  • 01/13/202211/30/2022

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2…

[nemo-toolkit] Path Traversal in nemo-toolkit

  • Posted inMODERATE
  • Posted byGitHub
  • 01/11/202209/08/2022

NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available.
References

https://github.com/NVIDIA/NeMo/security/advisories/GHSA-rpx7-33j2-xx9x
h…

[k8s.io/kubernetes/pkg/kubectl] ANSI escape characters not filtered

  • Posted inLOW
  • Posted byGitHub
  • 01/08/202210/10/2022

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
References

https://nvd.nist.gov/vuln/detail…

チップセットが強化された新しいAcer Chromebook Spin 513が登場

  • Posted inUncategorized
  • Posted byUbergizmo Japan
  • 01/05/2022

通常、ディスプレイというと、より大きくなるほど高価になります。これは、モニターやテレビ、勿論ラップト…

[org.apache.logging.log4j:log4j-core] Improper Input Validation and Injection in Apache Log4j2

  • Posted inMODERATE
  • Posted byGitHub
  • 01/05/202210/06/2022

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to an attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JD…

超静音の高静圧冷却を実現!もちろん光る!ゲーミング冷却ファン「Razer Kunai Chroma」登場!

  • Posted inUncategorized
  • Posted byFunglr Games(日本語)
  • 01/04/2022

もはや光らないものはないレベルで様々なアイテムを光らせているゲーミングデバイス界隈。全てのものを光ら…

【追跡デジタルニッポン】 富士登山者へ導入が検討されている顔認証スキームとは?

  • Posted inUncategorized
  • Posted byねっと特報
  • 01/04/2022

顔認証が今、静かに広がっている。行政と民間企業が連携した実証実験も日本各地で行われている。新型コロナ…

[dolibarr/dolibarr] Cross site scripting in dolibarr

  • Posted inMODERATE
  • Posted byGitHub
  • 01/03/202209/08/2022

admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-22293
https://github.com/mustgundogdu/Research/blob/main/Dolibar_7.0.2-StoredXSS/REA…

Posts navigation

Previous Posts 1 2 3 4
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close