Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[feathers-sequelize] PENDING feathers-sequelize contains improper input validation leading to SQL injection

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/26/202211/01/2022

Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2422
https://c…

[shescape] Inefficient Regular Expression Complexity in shescape

  • Posted inHIGH
  • Posted byGitHub
  • 10/26/202211/01/2022

Impact
This impacts users that use shescape to escape arguments:

for the Unix shell Bash, or any not-officially-supported Unix shell;
using the escape or escapeAll functions with the interpolation option set to true.

An attacker can cause polynomial …

[evm] Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)

  • Posted inMODERATE
  • Posted byGitHub
  • 10/26/202211/01/2022

Impact
A custom stateful precompile can use the is_static parameter to determine if the call is executed in a static context (via STATICCALL), and thus decide if stateful operations should be done. Previously, the passed is_static parameter was incorre…

[github.com/flipped-aurora/gin-vue-admin/server] Gin-vue-admin subject to Remote Code Execution via file upload vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/26/202210/28/2022

Impact
Gin-vue-admin < 2.5.4 has File upload vulnerabilities。
File upload vulnerabilities are when a web server allows users to upload files to its filesystem without sufficiently validating things like their name, type, contents, or size. Failing t…

[github.com/zalando/skipper] Skipper vulnerable to SSRF via X-Skipper-Proxy

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/26/202210/26/2022

Impact
Skipper prior to version v0.13.236 is vulnerable to server-side request forgery (SSRF). An attacker can exploit a vulnerable version of proxy to access the internal metadata server or other unauthenticated URLs by adding an specific header (X-Sk…

[matrix-sdk] matrix-sdk 0.6.0 logs access tokens

  • Posted inMODERATE
  • Posted byGitHub
  • 10/26/202210/26/2022

When sending Matrix requests using an affected version of matrix-sdk in an application that writes logs using tracing-subscriber (in a way that includes fields of tracing spans such as tracing_subscribers default text output from the fmt module), these…

[@dependencytrack/frontend] @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details

  • Posted inMODERATE
  • Posted byGitHub
  • 10/26/202210/26/2022

Description
Due to the common practice of providing vulnerability details in markdown format, the Dependency-Track frontend renders them using the JavaScript library Showdown. Showdown does not have any XSS countermeasures built in, and versions before…

[github.com/openfga/openfga] OpenFGA Authorization Bypass via tupleset wildcard

  • Posted inMODERATE
  • Posted byGitHub
  • 10/26/202210/28/2022

Overview
During our internal security assessment, it was discovered that OpenFGA versions v0.2.3 and prior are vulnerable to authorization bypass under certain conditions.
Am I affected?
You are affected by this vulnerability if you are using openfga/o…

[github.com/openfga/openfga] OpenFGA Authorization Bypass

  • Posted inMODERATE
  • Posted byGitHub
  • 10/26/202210/28/2022

Overview
During our internal security assessment, it was discovered that OpenFGA versions v0.2.3 and prior are vulnerable to authorization bypass under certain conditions.
Am I Affected?
You are affected by this vulnerability if you are using openfga/o…

[github.com/openfga/openfga] OpenFGA subject to Information Disclosure via streamed-list-objects endpoint

  • Posted inMODERATE
  • Posted byGitHub
  • 10/26/202210/28/2022

Overview
During our internal security assessment, it was discovered that streamed-list-objects endpoint was not validating the authorization header resulting in the disclosure of objects in the store.
Am I Affected?
You are affected by this vulnerabili…

Posts navigation

Previous Posts 1 … 22 23 24 25 26 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close