Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[pagekit/pagekit] Pagekit vulnerable to Unrestricted Upload of File with Dangerous Type

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/21/202209/23/2022

A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38916
https://github.com/pagekit/pagekit/issues/970
https://github.com…

[pywasm3] WASM3 Improper Input Validation vulnerability

  • Posted inLOW
  • Posted byGitHub
  • 09/21/202209/22/2022

WASM3 v0.5.0 was discovered to contain a segmentation fault via the component op_Select_i32_srs in wasm3/source/m3_exec.h.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-39974
https://github.com/wasm3/wasm3/issues/379
https://github.com/wasm3/wa…

[steal] steal Inefficient Regular Expression Complexity vulnerability via string variable

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/24/2022

A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37259
https://github.com/stealjs/steal/issues/1528
https://github.com/stealj…

[steal] steal vulnerable to Prototype Pollution via alias variable

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/21/202209/24/2022

Prototype pollution vulnerability in stealjs steal via the alias variable in babel.js.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37265
https://github.com/stealjs/steal/issues/1534
https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf…

[github.com/drakkan/sftpgo] SFTPGo WebClient vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 09/21/202209/24/2022

Impact
Cross-site scripting (XSS) vulnerabilities have been reported to affect SFTPGo WebClient. If exploited, this vulnerability allows remote attackers to inject malicious code.
Patches
Fixed in v2.3.5.
References

https://github.com/drakkan/sftpgo/s…

[org.xwiki.platform:xwiki-platform-oldcore] XWiki.WebHome vulnerable to Improper Privilege Management in XWiki resolving groups

  • Posted inHIGH
  • Posted byGitHub
  • 09/21/2022

Impact
It’s possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation.
More specifically, editing a right with the object editor leads to adding a supplementary empty value to groups which is then resolved as a refer…

[org.xwiki.platform:xwiki-platform-security] XWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same reference

  • Posted inHIGH
  • Posted byGitHub
  • 09/21/202209/21/2022

Impact
A bug in the security cache is storing rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry.
That means that it’s possible to overwrite the rights of a space or a document by creating the page of the space with …

[@fastly/js-compute] Fastly Compute@Edge JS Runtime has fixed random number seed during compilation

  • Posted inHIGH
  • Posted byGitHub
  • 09/21/202209/22/2022

Impact
Math.random and crypto.getRandomValues methods failed to use sufficiently random values. The initial value to seed the CSPRNG (cryptographically secure pseudorandom number generator) was baked-in to the final WebAssembly module meaning the seque…

[github.com/cri-o/cri-o] CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure

  • Posted inHIGH
  • Posted byGitHub
  • 09/20/202209/23/2022

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to …

[valine] Valine code injection vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/20/202209/24/2022

Valine was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38545
https://github.com/xCss/Valine/issues/…

Posts navigation

Previous Posts 1 … 51 52 53 54 55 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close