Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[apache-airflow] Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API

  • Posted inHIGH
  • Posted byGitHub
  • 10/08/202210/20/2022

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn’t prevent an already authenticated user from being able to continue using the UI or API.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-41672
https://github.com/apache/airflow…

[nocodb] NocoDB vulnerable to Denial of Service

  • Posted inMODERATE
  • Posted byGitHub
  • 10/08/202210/11/2022

NocoDB prior to 0.92.0 allows actors to insert large characters into the input field New Project on the create field, which can cause a Denial of Service (DoS) via a crafted HTTP request. Version 0.92.0 fixes this issue.
References

https://nvd.nist.go…

[v8n] v8n vulnerable to Inefficient Regular Expression Complexity

  • Posted inHIGH
  • Posted byGitHub
  • 10/07/202210/07/2022

Impact
Inefficient regular expression complexity of lowercase() and uppercase() regex could lead to a denial of service attack. With a formed payload ‘a’ + ‘a’.repeat(i) + ‘A’, only 32 characters payload could take 29443 ms time execution when testing …

[twisted] Twisted vulnerable to HTTP Request Smuggling Attacks

  • Posted inMODERATE
  • Posted byGitHub
  • 10/07/202210/07/2022

Impact
Twisted Web is vulnerable to request smuggling attacks:

“When presented with two content-length headers, Twisted Web ignored the first header. When the second content-length was set to zero this caused Twisted Web to interpret the request body …

[Flask-Security] Flask-Security vulnerable to Open Redirect

  • Posted inMODERATE
  • Posted byGitHub
  • 10/07/202210/07/2022

This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such …

[github.com/supranational/blst] Blst vulnerable to incorrect results for some inputs in blst_fp_eucl_inverse function

  • Posted inMODERATE
  • Posted byGitHub
  • 10/07/202210/07/2022

Impact
Blst versions v0.3.0 to v0.3.2 can produce the incorrect outputs for some inputs to the blst_fp_eucl_inverse function. This could theoretically result in the creation of an invalid signature from correct inputs. However, fuzzing of higher level …

[github.com/tendermint/tendermint/evidence] Tendermint Core vulnerable to Uncontrolled Resource Consumption

  • Posted inMODERATE
  • Posted byGitHub
  • 10/07/202210/07/2022

Description
Tendermint Core v0.34.0 introduced a new way of handling evidence of misbehavior. As part of this, we added a new Timestamp field to Evidence structs. This timestamp would be calculated using the same algorithm that is used when a block is …

[tensorflow] TensorFlow vulnerable to heap out of bounds read in filesystem glob matching

  • Posted inHIGH
  • Posted byGitHub
  • 10/07/202210/07/2022

Impact
The general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the directories:
if (!fs->Match(child_path, dirs[dir_index])) { … }

Since dir_index is unconditional…

[github.com/antchfx/xmlquery] xmlquery lacks check for whether LoadURL response is in XML format, causing denial of service

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/07/2022

xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.
References

https://nvd.nist…

[github.com/russellhaering/goxmldsig] goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures

  • Posted inHIGH
  • Posted byGitHub
  • 10/07/2022

This affects all versions of package github.com/russellhaering/goxmldsig prior to 1.1.1. There is a crash on nil-pointer dereference caused by sending malformed XML signatures. This issue is patched in version 1.1.1.
References

https://nvd.nist.gov/vu…

Posts navigation

Previous Posts 1 … 34 35 36 37 38 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close