Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[org.webjars.npm:vuetify] Vuetify Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 09/19/202209/22/2022

The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the ‘eventName’ function within the VCalendar component.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-25…

[snipe/snipe-it] Snipe-IT vulnerable to Improper Authentication

  • Posted inMODERATE
  • Posted byGitHub
  • 09/18/202209/23/2022

Snipe-IT prior to 6.0.10 is vulnerable to Improper Authentication. A user without the View and Modify License Files permission may access files uploaded to licenses as long as they have the View permission for licenses.
References

https://nvd.nist.gov…

[librenms/librenms] LibreNMS stored Cross-site Scripting via Schedule Maintenance `Title` parameter

  • Posted inMODERATE
  • Posted byGitHub
  • 09/18/202209/21/2022

LibreNMS versions 22.8.0 and prior allow attackers to execute arbitrary JavaScript code via the Schedule Maintenance Title parameter. A patch is available and anticipated to be part of version 22.9.0.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[rdiffweb] rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users

  • Posted inMODERATE
  • Posted byGitHub
  • 09/18/202209/23/2022

rdiffweb prior to 2.4.5 is vulnerable to Cross-Site Request Forgery (CSRF). An attacker exploiting this vulnerability can use it to delete repositories and users.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3232
https://github.com/ikus060/rdi…

[com.fasterxml.woodstox:woodstox-core] Denial of Service due to parser crash

  • Posted inLOW
  • Posted byGitHub
  • 09/17/202210/26/2022

Those using FasterXML/woodstox to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may …

[com.fasterxml.woodstox:woodstox-core] Denial of Service due to parser crash

  • Posted inLOW
  • Posted byGitHub
  • 09/17/202210/26/2022

Those using FasterXML/woodstox to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may …

[org.codehaus.jettison:jettison] Jettison parser crash by stackoverflow

  • Posted inMODERATE
  • Posted byGitHub
  • 09/17/202210/19/2022

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect…

[com.fasterxml.woodstox:woodstox-core] Denial of Service via stack overflow

  • Posted inLOW
  • Posted byGitHub
  • 09/17/202210/26/2022

Those using FasterXML/woodstox to serialise XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect ma…

[com.fasterxml.woodstox:woodstox-core] Denial of Service via stack overflow

  • Posted inLOW
  • Posted byGitHub
  • 09/17/202210/26/2022

Those using FasterXML/woodstox to serialise XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect ma…

[org.codehaus.jettison:jettison] Jettison memory exhaustion

  • Posted inLOW
  • Posted byGitHub
  • 09/17/202209/30/2022

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect…

Posts navigation

Previous Posts 1 … 52 53 54 55 56 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close