Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[com.zaxxer:nuprocess] NuProcess vulnerable to command-line injection through insertion of NUL character(s)

  • Posted inHIGH
  • Posted byGitHub
  • 09/30/202209/30/2022

Impact
In all the versions of NuProcess where it forks processes by using the JVM’s Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in their strings to perform command line injection. Java’s ProcessBuilder isn’t…

[matrix-js-sdk] matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion

  • Posted inHIGH
  • Posted byGitHub
  • 09/30/202210/04/2022

Impact
An attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield.
Additionally, a sophisticated attacker cooperating with a malicio…

[matrix-js-sdk] matrix-js-sdk subject to impersonated messages due to permissive key forwarding

  • Posted inHIGH
  • Posted byGitHub
  • 09/30/202209/30/2022

Impact
An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.
This attack is possible …

[rdiffweb] rdiffweb vulnerable to password complexity bypass leading to weak passwords

  • Posted inMODERATE
  • Posted byGitHub
  • 09/30/202210/05/2022

ikus060/rdiffweb prior to 2.4.9 allows a user to set there password to all spaces. While rdiffweb has a password policy requiring passwords to be between 8 and 128 characters, it does not validate the password entropy, allowing users to bypass password…

[inventree] Inventree vulnerable to Stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 09/30/202210/04/2022

Inventree prior to 0.8.3 is vulnerable to stored cross-site scripting by uploading SVG files. Version 0.8.3 contains a patch for this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3355
https://github.com/inventree/inventree/commit/5a08ef…

[feehi/feehicms] FeehiCMS vulnerable to Cross-Site scripting via crafted payload

  • Posted inMODERATE
  • Posted byGitHub
  • 09/30/202210/05/2022

FeehiCMS versions 2.0.1.1 and prior contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module. There are no patches and no known workarounds for this issue.
References

https://n…

[github.com/dutchcoders/transfer.sh] Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload

  • Posted inMODERATE
  • Posted byGitHub
  • 09/30/202210/05/2022

dutchcoders Transfer.sh versions 1.4.0 and prior are vulnerable to Cross Site Scripting (XSS) via a malicious document uploaded in transfer.sh. There is a fix commit merged into main for this issue, but an updated version has not yet been released.
Re…

[rdiffweb] rdiffweb’s unlimited length Fullname field can lead to DoS

  • Posted inMODERATE
  • Posted byGitHub
  • 09/30/202210/05/2022

rdiffweb prior to 2.5.0a3 does not validate email length, allowing users to insert an email longer than 255 characters. If a user signs up with an email with a length of 1 million or more characters and logs in, withdraws, or changes their email, the s…

[com.amazon.redshift:redshift-jdbc42] AWS Redshift JDBC Driver fails to validate class type during object instantiation

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/30/202210/05/2022

In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name. This issue has been fixed in version 2.1.0.8.
Refer…

[matrix-js-sdk] Improper beacon events in matrix-js-sdk can result in availability issues

  • Posted inMODERATE
  • Posted byGitHub
  • 09/29/202209/29/2022

Impact
Improperly formed beacon events (from MSC3488) can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer’s ability to process data safely. Note that the matrix-js-sdk can appear to be operating normall…

Posts navigation

Previous Posts 1 … 40 41 42 43 44 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close