Skip to content

トピトピニュース

Header Image
Archive

Month: May 2022

251 Posts

Featured

Posted byByakuya Biz Books
シンガポール発のコーヒーチェーン「フラッシュコーヒー」が2年で250店舗に拡大した理由
Posted byGoogle Japan Blog
個人情報を考える週間: パスワードとオンライン アカウントを安全に保つためのヒント
Posted byねっと特報
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byFunglr Games(日本語)
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!

[io.undertow:undertow-core] Undertow Uncaught Exception vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/08/2022

A long URL proxy request lead to java.nio.BufferOverflowException in Undertow.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-7046
https://bugzilla.redhat.com/show_bug.cgi?id=1376646
https://github.com/undertow-io/undertow/commit/c518b5a1784061d…

バットマン亡き後のゴッサム・シティを描く「ゴッサム・ナイツ」が2022年10月25日(火)に発売決定!

  • Posted inUncategorized
  • Posted byFunglr Games(日本語)
  • 05/14/2022

ゴッサム・シティを舞台にした新作オープンワールドアクションRPG「ゴッサム・ナイツ」当初は2021年…

[org.jenkins-ci.main:jenkins-core] Cross-site Scripting in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
References…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information in Jenkins Core

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.
References

https://nvd.nist.gov/vuln/d…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
References

https://nvd.nist…

[org.jenkins-ci.main:jenkins-core] Missing permissions check in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (s…

[org.jenkins-ci.main:jenkins-core] Incorrect Authorization in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the “full name.”
References

https://nvd.nist.gov/vuln/detail/CVE-2016-3722
https://access.redha…

[org.apache.drill:drill-common] Apache Drill vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/08/2022

In Apache Drill 1.11.0 and earlier, when submitting form from Query page, users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Q…

[commons-fileupload:commons-fileupload] Arbitrary file write in Apache Commons Fileupload

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/04/2022

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in …

Posts navigation

Previous Posts 1 … 10 11 12 13 14 … 26 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close