Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[github.com/shamaton/msgpack/v2] MessagePack for Golang subject to DoS via Unmarshal panic

  • Posted inHIGH
  • Posted byGitHub
  • 11/11/202211/16/2022

Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. This issue has been patched in version 2.1.1.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-41719
https://github.com/shamaton/msgpack/issues/31
https://github….

[arches] Arches vulnerable to execution of arbitrary SQL

  • Posted inHIGH
  • Posted byGitHub
  • 11/11/202211/14/2022

Impact
With a carefully crafted web request, it’s possible to execute certain unwanted sql statements against the database.Anyone running the impacted versions (<=6.1.1, 6.2.0, >=7.0.0, <=7.1.1) should upgrade as soon as possible.
Workarounds
…

[github.com/moby/moby] Container build can leak any path on the host into the container

  • Posted inLOW
  • Posted byGitHub
  • 11/11/202211/11/2022

Description
Moby is the open source Linux container runtime and set of components used to build a variety of downstream container runtimes, including Docker CE, Mirantis Container Runtime (formerly Docker EE), and Docker Desktop. Moby allows for buildi…

[ezsystems/ezpublish-kernel] eZ Platform users with the Company admin role can assign any role to any user

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/11/202211/11/2022

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have…

[ezsystems/ezplatform-kernel] eZ Platform users with the Company admin role can assign any role to any user

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/11/202211/11/2022

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have…

[ezsystems/repository-forms] eZ Platform users with the Company admin role can assign any role to any user

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/11/2022

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have…

[ezsystems/ezplatform-admin-ui] eZ Platform users with the Company admin role can assign any role to any user

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/11/202211/11/2022

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have…

[ibexa/admin-ui] Ibexa DXP users with the Company admin role can assign any role to any user

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/11/202211/11/2022

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have…

[ibexa/core] Ibexa DXP users with the Company admin role can assign any role to any user

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/11/2022

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have…

[ibexa/admin-ui] ibexa/admin-ui vulnerable to Cross-site Scripting in content type name/shortname

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/11/202211/11/2022

Critical severity. It is possible to inject JavaScript XSS in the content type entries “name” and “short name”. To exploit this, one must already have permission to edit content types, which limits it in many cases to people who are already administrat…

Posts navigation

Previous Posts 1 … 11 12 13 14 15 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close