Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[org.ini4j:ini4j] org.ini4j allows attackers to cause a Denial of Service (DoS)

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202210/19/2022

An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-41404
https://sourceforge.net/p/ini4j…

[org.apache.shiro:shiro-core] Apache Shiro Authentication Bypass vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/12/202210/14/2022

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-40664
https://lists.apache.org/thread/loc2ktxng32xpy7lfwxto13k4lvnhjwg
ht…

[NuGet.Commands] NuGet Elevation of Privilege Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202210/15/2022

Description
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0.0-rc, .NET 6.0, .NET Core 3.1, and NuGet (NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.Protocol). This advisory also provides guid…

[melisplatform/melis-asset-manager] melisplatform/melis-asset-manager vulnerable to Path Traversal

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202210/15/2022

Impact
Attackers can read arbitrary files on affected versions of melisplatform/melis-asset-manager, leading to the disclosure of sensitive information. Conducting this attack does not require authentication.
Users should immediately upgrade to melispl…

[melisplatform/melis-cms] melisplatform/melis-cms vulnerable to deserialization of untrusted data

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202210/14/2022

Impact
Attackers can deserialize arbitrary data on affected versions of melisplatform/melis-cms, and ultimately leads to the execution of arbitrary PHP code on the system. Conducting this attack does not require authentication.
Users should immediately…

[melisplatform/melis-front] melisplatform/melis-front vulnerable to deserialization of untrusted data

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202210/14/2022

Impact
Attackers can deserialize arbitrary data on affected versions of melisplatform/melis-front, and ultimately leads to the execution of arbitrary PHP code on the system. Conducting this attack does not require authentication.
Users should immediate…

[xmldom] Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) in @xmldom/xmldom and xmldom

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/12/202210/19/2022

Impact
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package.
Patches
Update to @xmldom/xmldom@~0.7.6, @xmldom/xmldom@~0.8.3 (dist-tag latest) or @xmldom/xmldom@>=0.9.0-beta.2 (…

[poetry] Poetry vulnerable to Untrusted Search Path leading to Local Code Execution on Windows

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202210/12/2022

Observation
To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. git config. These commands are being executed using the executable’s name and not its absolute path.
This can lead to the execution of untrusted …

[django-mfa2] django-mfa2 vulnerable to MFA Replay attack

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202210/13/2022

mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage.
References

https://nvd.nist.gov/vuln/det…

[openssl-src] Using a Custom Cipher with `NID_undef` may lead to NULL encryption

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202211/02/2022

OpenSSL supports creating a custom cipher via the legacy EVP_CIPHER_meth_new() function and associated function calls. This function was deprecated in OpenSSL 3.0 and application authors are instead encouraged to use the new provider mechanism in order…

Posts navigation

Previous Posts 1 … 32 33 34 35 36 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close