Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[django-mfa2] django-mfa2 vulnerable to MFA Replay attack

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202210/13/2022

mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage.
References

https://nvd.nist.gov/vuln/det…

[openssl-src] Using a Custom Cipher with `NID_undef` may lead to NULL encryption

  • Posted inHIGH
  • Posted byGitHub
  • 10/12/202211/02/2022

OpenSSL supports creating a custom cipher via the legacy EVP_CIPHER_meth_new() function and associated function calls. This function was deprecated in OpenSSL 3.0 and application authors are instead encouraged to use the new provider mechanism in order…

[metro4] Cross site scripting in Metro UI

  • Posted inMODERATE
  • Posted byGitHub
  • 10/12/202210/13/2022

Metro UI v4.4.0 to v4.5.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function. User input is not properly sanitized before rendering in the textarea component.
References

https://nvd.nist.gov/vuln…

[fastify] fastify vulnerable to denial of service via malicious Content-Type

  • Posted inHIGH
  • Posted byGitHub
  • 10/11/202210/17/2022

Impact
An attacker can send an invalid Content-Type header that can cause the application to crash, leading to a possible Denial of Service attack. Only the v4.x line is affected.
(This was updated: upon a close inspection, v3.x is not affected after a…

[github.com/traefik/traefik/v2] Traefik HTTP/2 connections management could cause a denial of service

  • Posted inHIGH
  • Posted byGitHub
  • 10/11/202210/14/2022

Impact
There is a potential vulnerability in Traefik managing HTTP/2 connections.
A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service.
Patches
Trae…

[slack-morphism] Exposure of sensitive Slack webhook URLs in debug logs and traces

  • Posted inHIGH
  • Posted byGitHub
  • 10/11/202210/11/2022

Impact
Debug logs expose sensitive URLs for Slack webhooks that contain private information.
Patches
The problem is fixed in v1.3.2 which redacts sensitive URLs for webhooks.
Workarounds
Disabling/filtering debug logs in case you use Slack webhooks usi…

[csrf-csrf] Incorrect default cookie name and recommendation

  • Posted inLOW
  • Posted byGitHub
  • 10/11/202210/11/2022

Impact
What kind of vulnerability is it? Who is impacted?
The default cookie name (and documentation recommendation) was prefixed with Host__ instead of __Host-. The point of this prefix is for additional security, to ensure that, when no domain option…

[rdiffweb] rdiffweb vulnerable to Open Redirect

  • Posted inMODERATE
  • Posted byGitHub
  • 10/11/202210/12/2022

A lack of user input validation leads to an open redirect vulnerability in rdiffweb prior to 2.5.0a4.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3438
https://github.com/ikus060/rdiffweb/commit/4d464b467f14b8eb9103d7f5f0774e49995527c7
https:/…

[tiny-csrf] tiny-csrf has openly visible CSRF tokens

  • Posted inHIGH
  • Posted byGitHub
  • 10/08/202210/20/2022

Impact
Weak encryption on CSRF so tokens can be read by malicious attackers.
Patches
Problems have been patched as of v1.1.0
Workarounds
Upgrade to v1.1.0
References
https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_…

[fat_free_crm] Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint

  • Posted inMODERATE
  • Posted byGitHub
  • 10/08/202210/20/2022

Impact
An authenticated user can perform a remote Denial of Service attack against Fat Free CRM.
This vulnerability has been assigned the CVE identifier: CVE-2022-39281
Affected versions: All
Not affected: None
Fixed versions: 0.20.1
All users running …

Posts navigation

Previous Posts 1 … 33 34 35 36 37 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close