Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[github.com/mattermost/mattermost-server] Denial of service in Mattermost

  • Posted inMODERATE
  • Posted byGitHub
  • 11/23/202211/27/2022

A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4044
https://hackerone.com/reports/1680241
https://matterm…

[backdrop/backdrop] Cross-site Scripting in Backdrop CMS

  • Posted inMODERATE
  • Posted byGitHub
  • 11/23/202211/27/2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-42095
https://github.com/backdrop/backdrop/releases/tag/1.23.0
https://g…

[io.quarkus:quarkus-parent] Code injection in quarkus dev ui config editor

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/23/202211/27/2022

A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4116
https://access.redha…

[backdrop/backdrop] Cross-site Scripting in Backdrop CMS

  • Posted inMODERATE
  • Posted byGitHub
  • 11/23/202211/23/2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via ‘Comment.’s
References

https://nvd.nist.gov/vuln/detail/CVE-2022-42097
https://github.com/backdrop/backdrop/releases/tag/1.23.0
https://github….

[microweber/microweber] Account Takeover Through Password Reset Poisoning

  • Posted inHIGH
  • Posted byGitHub
  • 11/23/202211/29/2022

Microweber 1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-33012
https://blog.jitendrapatro.me/cve-2022-33012-account-takeover-through-pas…

[backdrop/backdrop] Cross-site Scripting in Backdrop CMS

  • Posted inMODERATE
  • Posted byGitHub
  • 11/23/202211/24/2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the ‘Card’ content.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-42094
https://github.com/backdrop/backdrop/releases/tag/1.23.0
https:/…

[apache-airflow] OS Command Injection in Apache Airflow

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/22/202211/30/2022

Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access …

[apache-airflow] OS Command Injection in Apache Airflow

  • Posted inHIGH
  • Posted byGitHub
  • 11/22/202211/30/2022

Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write acces…

[apache-airflow] OS Command Injection in Apache Airflow

  • Posted inHIGH
  • Posted byGitHub
  • 11/22/202211/29/2022

Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access…

[apache-airflow] OS Command Injection in Apache Airflow

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/29/2022

Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to D…

Posts navigation

Previous Posts 1 2 3 4 5 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close