Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[apache-airflow] Apache Airflow Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/09/2022

In Apache Airflow versions prior to 2.4.2, the “Trigger DAG with config” screen was susceptible to XSS attacks via the origin query argument.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43982
https://github.com/apache/airflow/pull/27143
https…

[apache-airflow] Apache Airflow Open Redirect vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/09/2022

In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver’s /confirm endpoint.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43985
https://github.com/apache/airflow/pull/27143
https://lists.apache.org/thread/m13y9s5…

[centreon/centreon] Centreon vulnerable to SQL Injection

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/03/202211/05/2022

A SQL injection vulnerability in Centreon affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated remotely. Version 22.10.0-b…

[org.apache.sling:org.apache.sling.cms] Apache Sling App CMS vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/04/2022

A Cross-site Scripting vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.
References

https://nvd.nist.gov/vuln/…

[apollo-server-core] Batched HTTP requests may set incorrect `cache-control` response header

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/03/2022

Impact
In Apollo Server 3 and 4, the cache-control HTTP response header may not reflect the cache policy that should apply to an HTTP request when that HTTP request contains multiple operations using HTTP batching. This could lead to data being inappro…

[fluentd] fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)

  • Posted inLOW
  • Posted byGitHub
  • 11/03/202211/08/2022

Impact
A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads.
Fluentd setups are only affected if the environment variable FL…

[ckb] ckb type_id script resume may randomly fail

  • Posted inHIGH
  • Posted byGitHub
  • 11/03/202211/03/2022

Impact
https://github.com/nervosnetwork/ckb/blob/v0.101.2/script/src/verify.rs#L871-L879
TypeIdSystemScript resume handle is not correct when max_cycles is not enough, ScriptError::ExceededMaximumCycles will be raised directly ranther than suspend as e…

[ckb] ckb: Transaction header_deps validation issue (network forking)

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/03/202211/03/2022

Impact
fn HeaderChecker#check_valid skipped main chain checking after this PR: https://github.com/nervosnetwork/ckb/pull/1646/files#diff-c4e017b67c1b3005ca0c446a9b0879571aa36a858b1f7ddd1b9328a884e3214bR171-R176
It will cause network forking if one tran…

[ckb] ckb: Large dep group requires a lot of resources to process but the cost to commit the transaction is very low.

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/03/2022

Impact
When a transaction contains a dep group with many cells, the resources required to process it are not linear to the transaction size nor spent script cycles.
Patches
In 0.43.3, nodes drop the transactions relayed to them when they contain a dep…

[cryptography] Vulnerable OpenSSL included in cryptography wheels

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/2022

pyca/cryptography’s wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-38.0.3 are vulnerable to a number of security issues. More details about the vulnerabilities themselves can be found in http…

Posts navigation

Previous Posts 1 … 17 18 19 20 21 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close