Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[loader-utils] Prototype pollution in webpack loader-utils

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/13/202211/08/2022

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37601
https://github.com/webpack/load…

[powerline-gitstatus] Powerline Gitstatus vulnerable to arbitrary code execution

  • Posted inHIGH
  • Posted byGitHub
  • 10/13/202210/19/2022

powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When using powerline-gitstatus…

[node-saml] Signature bypass via multiple root elements

  • Posted inHIGH
  • Posted byGitHub
  • 10/13/202210/15/2022

Impact
A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticate…

[node-saml] Signature bypass via multiple root elements

  • Posted inHIGH
  • Posted byGitHub
  • 10/13/202210/18/2022

Impact
A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticate…

[com.enonic.xp:lib-auth] com.enonic.xp:lib-auth vulnerable to Session Fixation

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/13/202210/13/2022

Impact
All id-providers using lib-auth login method. lib-auth should invalidate old session after login and replicate session attributes in a new one, however this is not the behavior in affected versions.
Workarounds
Don’t use lib-auth for login.
Jav…

[dolibarr/dolibarr] Dolibarr vulnerable to Eval Injection

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/13/202210/18/2022

Dolibarr ERP & CRM <=15.0.3 are vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eva…

[com.amazon.redshift:redshift-jdbc42] com.amazon.redshift:redshift-jdbc42 vulnerable to remote command execution

  • Posted inHIGH
  • Posted byGitHub
  • 10/13/202210/13/2022

Impact
A potential remote command execution issue exists within redshift-jdbc42 versions 2.1.0.7 and below. When plugins are used with the driver, it instantiates plugin instances based on Java class names provided via the sslhostnameverifier, socketFa…

[apollo-server] The graphql-upload library included in Apollo Server 2 is vulnerable to CSRF mutations

  • Posted inMODERATE
  • Posted byGitHub
  • 10/12/202210/12/2022

Impact
The graphql-upload npm package can execute GraphQL operations contained in content-type: multipart/form-data POST requests. Because they are POST requests, they can contain GraphQL mutations. Because they use content-type: multipart/form-data, t…

[loader-utils] loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202211/23/2022

A regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils via the resourcePath variable in interpolateName.js. A badly or maliciously formed string could be used to send craf…

[github.com/hashicorp/nomad] Nomad Panics On Job Submission With Bad Artifact Stanza Source URL

  • Posted inMODERATE
  • Posted byGitHub
  • 10/12/202210/14/2022

HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
References

https://nvd.nist.gov/vuln/detail/C…

Posts navigation

Previous Posts 1 … 31 32 33 34 35 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close