Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[wger] wger vulnerable to brute force attempts

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/25/202212/01/2022

Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2650
https://github.com/wger-project/wger/commit/5e3167e3a2dc95836fa2607fe201524c031a2c…

[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files

  • Posted inMODERATE
  • Posted byGitHub
  • 11/24/202211/29/2022

Vulnerability
PreparedStatement.setText(int, InputStream)
and
PreparedStatemet.setBytea(int, InputStream)
will create a temporary file if the InputStream is larger than 51k
Example of vulnerable code:
String s = new String(“some very large string great…

[com.h2database:h2] Password exposure in H2 Database

  • Posted inMODERATE
  • Posted byGitHub
  • 11/24/202211/24/2022

The web-based admin console in H2 Database Engine through 2.1.214 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an at…

[sweetalert2] sweetalert2 v8.19.1 and above contains hidden functionality

  • Posted inLOW
  • Posted byGitHub
  • 11/24/202211/24/2022

sweetalert2 versions 8.19.1 and up until 9.0.0 are vulnerable to hidden functionality that was introduced by the maintainer. The package outputs audio and/or video messages that do not pertain to the functionality of the package and is not included in …

[sweetalert2] sweetalert2 v9.17.4 and above contains hidden functionality

  • Posted inLOW
  • Posted byGitHub
  • 11/24/2022

sweetalert2 versions 9.17.4 and up until 10.0.0 are vulnerable to hidden functionality that was introduced by the maintainer. The package outputs audio and/or video messages that do not pertain to the functionality of the package and is not included in…

[sweetalert2] sweetalert2 v10.16.10 and above contains hidden functionality

  • Posted inLOW
  • Posted byGitHub
  • 11/24/202211/24/2022

sweetalert2 versions 10.16.10 and up until 11.0.0 are vulnerable to hidden functionality that was introduced by the maintainer. The package outputs audio and/or video messages that do not pertain to the functionality of the package and is not included …

[moodle/moodle] Cross-Site Request Forgery in Moodle

  • Posted inMODERATE
  • Posted byGitHub
  • 11/24/202211/27/2022

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user’s CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A re…

[sweetalert2] sweetalert2 v11.4.9 and above contains hidden functionality

  • Posted inLOW
  • Posted byGitHub
  • 11/24/202211/24/2022

sweetalert2 versions 11.4.9 and above are vulnerable to hidden functionality that was introduced by the maintainer. The package outputs audio and/or video messages that do not pertain to the functionality of the package and is not included in versions …

[github.com/mattermost/mattermost-server] Denial of service in Mattermost

  • Posted inMODERATE
  • Posted byGitHub
  • 11/23/202211/27/2022

A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4045
…

[org.apache.dolphinscheduler:dolphinscheduler-alert-plugins] Command injection in Apache DolphinScheduler Alert Plugins

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/23/202211/27/2022

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-45462
https://lists….

Posts navigation

Previous Posts 1 2 3 4 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close