Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[silverstripe/admin] URL XSS vulnerability due to outdated jquery in CMS

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/2022

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38146
https://forum.silverstripe.org/c/releases
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstri…

[engine.io] Uncaught exception in engine.io

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/29/2022

Impact
A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.
events.js:292
throw er; // Unhandled ‘error’ event
^

Error: read ECONNRESET
at TCP.onStreamRead (inter…

[tensorflow] `CHECK` failure in `SobolSample` via missing validation

  • Posted inLOW
  • Posted byGitHub
  • 11/22/202211/22/2022

Impact
Another instance of CVE-2022-35935, where SobolSample is vulnerable to a denial of service via assumed scalar inputs, was found and fixed.
import tensorflow as tf
tf.raw_ops.SobolSample(dim=tf.constant([1,0]), num_results=tf.constant([1]), skip=…

[tensorflow-cpu] `CHECK` fail in `TensorListScatter` and `TensorListScatterV2` in eager mode

  • Posted inLOW
  • Posted byGitHub
  • 11/22/202211/22/2022

Impact
Another instance of CVE-2022-35991, where TensorListScatter and TensorListScatterV2 crash via non scalar inputs inelement_shape, was found in eager mode and fixed.
import tensorflow as tf
arg_0=tf.random.uniform(shape=(2, 2, 2), dtype=tf.float16…

[org.xwiki.platform:xwiki-platform-filter-ui] Missing Authorization in Filter Stream Converter Application

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/22/202211/23/2022

Impact
The application allow anyone with view access to modify any page of the wiki by importing a crafted XAR package.
Patches
The problem has been patched in XWiki 14.6RC1, 14.6 and 13.10.8.
Workarounds
The problem can be patched immediately by setti…

[org.xwiki.platform:xwiki-platform-rest-server] Exposure of Private Personal Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-rest-server

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/23/2022

Impact
The modifications rest endpoint does not filter out entries according to the user’s rights.
Therefore, information hidden from unauthorized users are exposed though the modifications rest endpoint (e.g., comments, page names…).
Patches
Users …

[org.xwiki.platform:xwiki-platform-livetable-ui] Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-ui

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/22/2022

Impact
User without the right to view documents can deduce their existence by repeated Livetable queries.
Reproduction steps

Restrict “view” access to Sandbox.TestPage3 by setting an explicit view right for admins
As a user who is not an admin, open &…

[org.xwiki.platform:xwiki-platform-menu-ui] Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’) in org.xwiki.platform:xwiki-platform-menu-ui

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/22/202211/22/2022

Impact
Any user with view rights on commonly accessible documents including the menu macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation due to improper escaping of the macro content and…

[org.xwiki.platform:xwiki-platform-security-authentication-default] Plaintext storage of password after a reset in org.xwiki.platform:xwiki-platform-security-authentication-default

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/22/2022

Impact
We discovered that when the reset a forgotten password feature of XWiki was used, the password was then stored in plain text in database. This only concerns XWiki 13.1RC1 and next versions.
Note that it only concerns the reset password feature a…

[org.xwiki.platform:xwiki-platform-oldcore] Creation of new database tables through login form on PostgreSQL

  • Posted inHIGH
  • Posted byGitHub
  • 11/22/202211/22/2022

Impact
It’s possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form.
Patches
The problem has been patched in XWiki 13.10.8, 14.6RC1 and 14.4.2.
Workarounds
The only workarounds …

Posts navigation

Previous Posts 1 … 3 4 5 6 7 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close