Skip to content

トピトピニュース

Header Image
Archive

Month: May 2022

251 Posts

Featured

Posted byByakuya Biz Books
シンガポール発のコーヒーチェーン「フラッシュコーヒー」が2年で250店舗に拡大した理由
Posted byGoogle Japan Blog
個人情報を考える週間: パスワードとオンライン アカウントを安全に保つためのヒント
Posted byねっと特報
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byFunglr Games(日本語)
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!

[org.apache.atlas:atlas-common] Path Traversal in Apache Atlas

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-8752
https://lists.apache.or…

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3153
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867…

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3152
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa…

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3155
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa65e2a0520acde71d…

[org.apache.atlas:atlas-common] Apache Atlas produces Stack trace in error response

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/05/2022

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3154
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da56…

[scrapy] Scrapy denial of service vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/08/2022

Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files are then individually written in a separate thread to…

[org.apache.struts:struts2-core] Incomplete exclude pattern in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/04/2022

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to “compromise internal state of an application” via unspecified vectors. In Struts 2.3.20.1 a better set of exlude patterns was defined.
References

https://nv…

[org.apache.geode:geode-core] Apache Geode gfsh query vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/08/2022

When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user’s concurrentl…

[mistune] Cross-site Scripting in Mistune

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202209/09/2022

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-15612
https://github.com/lepture…

[com.neovisionaries:nv-websocket-client] nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/08/2022

The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS s…

Posts navigation

Previous Posts 1 … 9 10 11 12 13 … 26 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close