Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[@fastify/websocket] fastify/websocket vulnerable to uncaught exception via crash on malformed packet

  • Posted inHIGH
  • Posted byGitHub
  • 11/08/202211/08/2022

Impact
Any application using @fastify/websocket could crash if a specific, malformed packet is sent.
All versions of fastify-websocket are also impacted. That module is deprecated, so it will not be patched.
Patches
This has been patched in v7.1.1 (fa…

[org.apache.bcel:bcel] Apache Commons BCEL vulnerable to out-of-bounds write

  • Posted inHIGH
  • Posted byGitHub
  • 11/08/202211/08/2022

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications …

[org.apache.ivy:ivy] Apache Ivy vulnerable to path traversal

  • Posted inHIGH
  • Posted byGitHub
  • 11/08/202211/08/2022

When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied “pattern” that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates conta…

[github.com/btcsuite/btcd] btcd mishandles witness size checking

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/07/202211/15/2022

btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witness size checking.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-44797
https://github.com/lightningnetwork/lnd/issues/7002
h…

[org.apache.ivy:ivy] Apache Ivy does not verify target path when extracting the archive

  • Posted inHIGH
  • Posted byGitHub
  • 11/07/202211/08/2022

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used
pack200 or zip packaging.
For artifacts using the “zip”, “jar” or “war” packaging Ivy prior to version 2.5.1 doesn’t …

[froxlor/froxlor] Froxlor vulnerable to code injection

  • Posted inMODERATE
  • Posted byGitHub
  • 11/06/202211/09/2022

Code Injection in GitHub repository froxlor/froxlor prior to version 0.10.38.2. There are currently no known workarounds, please upgrade to version 0.10.38.2.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3869
https://github.com/froxlor/froxlor…

[github.com/pingcap/tidb] TiDB vulnerable to Use of Externally-Controlled Format String

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/05/202211/06/2022

TiDB is vulnerable to Use of Externally-Controlled Format String. A patch is available on the master branch and expected to be part of versions 6.4.0 and 6.1.3.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3023
https://github.com/pingcap/tidb/…

[pulsar-client] Apache Pulsar: Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack

  • Posted inHIGH
  • Posted byGitHub
  • 11/05/202211/08/2022

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. This vulnerability allows an attacker to perform a m…

[froxlor/froxlor] Froxlor vulnerable to Code Injection

  • Posted inMODERATE
  • Posted byGitHub
  • 11/05/202211/15/2022

Froxlor prior to version 0.10.39 is vulnerable to Code Injection.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3721
https://github.com/froxlor/froxlor/commit/1182453c18a83309a3470b2775c148ede740806c
https://huntr.dev/bounties/a3c506f0-5f8a-4ea…

[org.xwiki.contrib.oidc:oidc-authenticator] XWiki OIDC Authenticator vulnerable to bypassing OpenID login by providing a custom provider

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/05/202211/06/2022

Impact
Even if a wiki has an OpenID provider configured through its xwiki.properties, it is possible to provide a third party provider by providing its details through request parameters. One can then bypass the XWiki authentication altogether by speci…

Posts navigation

Previous Posts 1 … 15 16 17 18 19 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close