Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[intelliants/subrion] Subrion CMS is vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/10/2022

A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS version 4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.
Ref…

[intelliants/subrion] Subrion CMS is vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/10/2022

A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS in version 4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
References

https://n…

[feehi/cms] FeehiCMS is vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/11/2022

FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43320
https://github.com/liufee/feehic…

[org.eclipse.californium:scandium] Failing DTLS handshakes may cause throttling to block processing of records

  • Posted inHIGH
  • Posted byGitHub
  • 11/10/202211/10/2022

Impact
Failing handshakes didn’t cleanup counters for throttling. In consequence the threshold may get reached and will not be released again. The results in permanently dropping records. The issues was reported for certificate based handshakes, but it…

[System.Data.SqlClient] .NET Information Disclosure Vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 11/09/202211/10/2022

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET, .NET Core and .NET Framework’s System.Data.SqlClient and Microsoft.Data.SqlClient NuGet Packages.
A vulnerability exists in System.Data.SqlClient and Mi…

[github.com/openfga/openfga] OpenFGA Authorization Bypass

  • Posted inMODERATE
  • Posted byGitHub
  • 11/09/202211/10/2022

Overview
During our internal security assessment, it was discovered that OpenFGA versions v0.2.4 and prior are vulnerable to authorization bypass under certain conditions.
Am I Affected?
You are affected by this vulnerability if you are using openfga/o…

[lzf] Invalid use of `mem::uninitialized` causes `use-of-uninitialized-value`

  • Posted inMODERATE
  • Posted byGitHub
  • 11/09/202211/09/2022

The compression and decompression function used mem:uninitialized to create an array of uninitialized values, to later write values into it. This later leads to reads from uninitialized memory.
The flaw was corrected in commit b633bf265e41c60dfce3be7ea…

[octocat.js] Withdrawn: Octocat.js vulnerable to code injection

  • Posted inHIGH
  • Posted byGitHub
  • 11/09/202211/10/2022

Withdrawn
This advisory has been withdrawn because it is a test.
Original Description
Impact
Users can include their own images for accessories via provided URLs. These URLs are not validated and can result in execution of injected code.
Patches
This v…

[Tauri] Tauri Filesystem Scope can be Partially Bypassed

  • Posted inLOW
  • Posted byGitHub
  • 11/09/202211/12/2022

Impact
Due to incorrect escaping of special characters in paths selected via the file dialog and drag and drop functionality, it was possible to partially bypass the fs scope definition. It was not possible to traverse into arbitrary paths, as the issu…

[parse-server] Remote code execution via MongoDB BSON parser through prototype pollution

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/09/202211/12/2022

Impact
An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.
Patches
Prevent prototype pollution in MongoDB database adapter.
Workarounds
Disable remote code execution through the MongoDB…

Posts navigation

Previous Posts 1 … 14 15 16 17 18 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close