Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[personnummer] personnummer/rust vulnerable to Improper Input Validation

  • Posted inLOW
  • Posted byGitHub
  • 09/22/202209/22/2022

This vulnerability was reported to the personnummer team in June 2020. The slow response was due to locked ownership of some of the affected packages, which caused delays to update packages prior to disclosure.
The vulnerability is determined to be low…

[yetiforce/yetiforce-crm] YetiForce CRM vulnerable to stored Cross-site Scripting via SlaPolicy module

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/22/2022

YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the SlaPolicy module. A patch is available at commit e55886781509fe39951fc7528347696474a17884.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3005
https://github.c…

[yetiforce/yetiforce-crm] YetiForce CRM vulnerable to stored Cross-site Scripting via WidgetsManagement module

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/22/2022

YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the WidgetsManagement module. A patch is available at commit b716ecea340783b842498425faa029800bd30420.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2924
https://…

[yetiforce/yetiforce-crm] YetiForce CRM vulnerable to stored Cross-site Scripting via WorkFlow module

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/22/2022

YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the WorkFlow module. A patch is available at commit cd82ecce44d83f1f6c10c7766bf36f3026de024a.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3004
https://github.co…

[microweber/microweber] Microweber Cross-site Scripting can result in redirection to a malicious site

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/22/2022

Microweber versions 1.3.1 and prior are vulnerable to HTML injection that an attacker can use to redirect someone to a malicious site. A patch is available at commit 68f0721571653db865a5fa01c7986642c82e919c and expected to be part of version 1.3.2.
Ref…

[org.apache.kafka:kafka] Apache Kafka vulnerability can lead to brokers hitting OutOfMemoryException, causing Denial of Service

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/22/2022

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemoryEx…

[yetiforce/yetiforce-crm] YetiForce CRM vulnerable to stored Cross-site Scripting via LayoutEditor module

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202210/01/2022

YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the LayoutEditor module. A patch is available at commit eebc12601495ada38495076bec12841b2477516b.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3000
https://githu…

[microweber/microweber] Microweber vulnerable to HTML Injection in create tag functionality

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/24/2022

HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input. A patch is avai…

[org.apache.inlong:inlong-common] Apache InLong vulnerable to Deserialization of Untrusted Data

  • Posted inHIGH
  • Posted byGitHub
  • 09/21/202209/22/2022

In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentiall…

[github.com/HFO4/cloudreve] Cross site scripting in Cloudreve

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/24/2022

Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.
References…

Posts navigation

Previous Posts 1 … 50 51 52 53 54 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close