Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[rdiffweb] rdiffweb Cross-Site Request Forgery vulnerability can lead to user email ID being changed

  • Posted inHIGH
  • Posted byGitHub
  • 09/23/202209/24/2022

rdiffwen prior to version 2.4.7 is vulnerable to Cross-Site Request Forgery (CSRF). An attacker can change a user’s email ID. Version 2.4.7 has a fix for this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3274
https://github.com/ikus060/…

[icecoder/icecoder] ICEcoder vulnerable to Path Traversal

  • Posted inHIGH
  • Posted byGitHub
  • 09/23/202209/27/2022

ICEcoder v8.1 allows attackers to execute a directory traversal.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-34026
https://gist.github.com/enferas/85cdbadf5cba32ec7c8db6ea9e6833bf
https://github.com/icecoder/ICEcoder/blob/master/classes/Setti…

[rdiffweb] rdiffweb Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 09/23/202209/24/2022

rdiffweb prior to 2.4.6 is vulnerable to cross-site request forgery on the repository settings. A malicious user can change the settings of a repository by sending a URL to the victim. This issue is fixed in version 2.4.6.
References

https://nvd.nist….

[tui-grid] Toast UI Grid vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 09/23/202210/02/2022

Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted content into editable cells. This issue was fixed in version 4.21.3. There are no known workar…

[apache-airflow] Apache Airflow vulnerable to Use of Externally-Controlled Format String

  • Posted inHIGH
  • Posted byGitHub
  • 09/23/2022

In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-40604
https://github.com/apache/airflow/pull/26337
https://github.com/…

[apache-airflow] Apache Airflow vulnerable to open redirect

  • Posted inMODERATE
  • Posted byGitHub
  • 09/23/202209/23/2022

In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver’s /confirm endpoint.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-40754
https://github.com/apache/airflow/pull/26409
https://github.com/pypa/advisory-database/t…

[OctoPrint] OctoPrint vulnerable to Unrestricted Upload of File with Dangerous Type

  • Posted inLOW
  • Posted byGitHub
  • 09/22/202209/27/2022

OctoPrint prior to version 1.8.3 is vulnerable to Unrestricted Upload of File with Dangerous Type. Due to misconfiguration in move file functionality, an attacker could easily change the file extension of an uploaded malicious file disguised as a .gcod…

[OctoPrint] OctoPrint Improper Privilege Management vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 09/22/202209/24/2022

OctoPrint prior to 1.8.3 allows a user with read access only to access a privileged user’s account and functionality. Version 1.8.3 contains a patch for this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3068
https://github.com/octoprint…

[OctoPrint] OctoPrint vulnerable to Insufficient Session Expiration.

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/24/2022

If an attacker comes into the possession of a victim’s OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim’s account exists. This issue is fixed in version 1.8.3.
References

https://n…

[pimcore/pimcore] Pimcore vulnerable to cross site scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/23/2022

If an attacker can control a script that is executed in the victim’s browser, then they can typically fully compromise that user. Amongst other things, the attacker can perform any action within the application that the user can perform; view any infor…

Posts navigation

Previous Posts 1 … 46 47 48 49 50 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close