Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[sqlite3] SQLite3 addresses vulnerability in packaged version of libsqlite

  • Posted inLOW
  • Posted byGitHub
  • 10/04/202210/04/2022

Summary
The rubygem sqlite3 v1.5.1 upgrades the packaged version of libsqlite from v3.39.3 to v3.39.4.
libsqlite v3.39.4 addresses a vulnerability described as follows in the release notification:

Version 3.39.4 is a minimal patch against the prior re…

[github.com/dexidp/dex] Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/04/202210/07/2022

Impact
Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability.
An attacker can exploit this vulnerability by making a victim navigate to a malicious website and gu…

[com.fasterxml.jackson.core:jackson-databind] Uncontrolled Resource Consumption in Jackson-databind

  • Posted inHIGH
  • Posted byGitHub
  • 10/03/202211/18/2022

In FasterXML jackson-databind before 2.12.7.1 and in 2.13.x before 2.13.4.1 resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is …

[com.fasterxml.jackson.core:jackson-databind] Uncontrolled Resource Consumption in FasterXML jackson-databind

  • Posted inHIGH
  • Posted byGitHub
  • 10/03/202211/19/2022

In FasterXML jackson-databind before 2.12.7.1 and in 2.13.x before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only wi…

[github.com/cloudflare/goflow/v3/decoders/sflow] Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package

  • Posted inHIGH
  • Posted byGitHub
  • 10/02/202210/05/2022

Impact
The sflow decode package prior to version 3.4.4 is vulnerable to a denial of service attack. Attackers can craft malformed packets causing the process to consume huge amounts of memory resulting in a denial of service.
Patches
Version 3.4.4 cont…

[DotNetNuke.Web] DNN vulnerable to Relative Path Traversal

  • Posted inMODERATE
  • Posted byGitHub
  • 10/01/202210/05/2022

DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2922
https://github.com/dnnsoftware/dnn.pla…

[css-what] css-what vulnerable to ReDoS due to use of insecure regular expression

  • Posted inHIGH
  • Posted byGitHub
  • 10/01/202210/05/2022

The package css-what before 2.1.3 is vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse f…

[react-native-reanimated] react-native-reanimated vulnerable to ReDoS

  • Posted inHIGH
  • Posted byGitHub
  • 10/01/202210/21/2022

The package react-native-reanimated before 3.0.0-rc.1 is vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-24373
http…

[rdiffweb] rdiffweb’s lack of token name length limit can result in DoS or memory corruption

  • Posted inHIGH
  • Posted byGitHub
  • 10/01/202210/05/2022

rdiffweb prior to 2.5.0a3 is vulnerable to Allocation of Resources Without Limits or Throttling. A lack of limit in the length of the Token name parameter can result in denial of service or memory corruption. Version 2.5.0a3 fixes this issue.
Reference…

[lief] LIEF vulnerable to denial of service through segmentation fault

  • Posted inMODERATE
  • Posted byGitHub
  • 10/01/202210/07/2022

A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file. A patch is available at commit number 24935f654f6df7…

Posts navigation

Previous Posts 1 … 38 39 40 41 42 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close