Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[com.liferay.portal:release.portal.bom] Incorrect Default Permissions in Liferay Portal

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remote authenticat…

[com.liferay.portal:release.portal.bom] Incorrect Default Permissions in Liferay Portal

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCo…

[concrete5/concrete5] Concrete CMS vulnerable to XML External Entity

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43689
https://documentation.concretecms.org/developers/in…

[com.liferay.portal:release.portal.bom] Authorization Bypass in Liferay Portal

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via t…

[com.liferay.portal:release.portal.bom] Improper Certificate Validation in Liferay Portal

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module’s REST data providers. This affects Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7…

[com.liferay.portal:release.portal.bom] Missing permissions check in Liferay Portal

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset librari…

[concrete5/concrete5] Concrete CMS vulnerable to Improper Authentication

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authentication bypass could occur if using this functionality. Remediate by updating to Concrete CMS 9.1.3+ or …

[com.liferay.portal:release.portal.bom] Inefficient Regular Expression Complexity in Liferay Portal

  • Posted inHIGH
  • Posted byGitHub
  • 11/15/202211/22/2022

ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of serve…

[com.liferay.portal:release.portal.bom] Incorrect Default Permissions in Liferay Portal

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.
R…

[soap:soap] Apache SOAP contains unauthenticated RPCRouterServlet

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/15/202211/19/2022

** UNSUPPORTED WHEN ASSIGNED ** In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on wha…

Posts navigation

Previous Posts 1 … 9 10 11 12 13 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close