Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[markdown-nice] Markdown-Nice v1.8.22 vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 09/10/202209/15/2022

A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38639
h…

[github.com/casdoor/casdoor] Casdoor arbitrary file write vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 09/10/202209/15/2022

Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38638
https://github.com/casdoor/casdoor/issues/1035
https://g…

[github.com/goharbor/harbor] Harbor fails to validate the user permissions when reading job execution logs through the P2P preheat execution logs

  • Posted inMODERATE
  • Posted byGitHub
  • 09/10/2022

Impact
Harbor fails to validate the user permissions when reading job execution logs through the P2P preheat execution logs – API call
  GET /projects/{project_name}/preheat/policies/{preheat_policy_name}/executions/{execution_id}/tasks/{task_id}/…

[org.apache.james:james-server] Apache James vulnerable to buffering attack

  • Posted inHIGH
  • Posted byGitHub
  • 09/09/202209/15/2022

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not ta…

[com.google.cloud.tools:jib-core] com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/09/202209/15/2022

The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-25914
https://github.c…

[rdiffweb] rdiffweb vulnerable to Improper Restriction of Rendered UI Layers or Frames

  • Posted inHIGH
  • Posted byGitHub
  • 09/09/202209/17/2022

rdiffweb prior to 2.4.1 is vulnerable to Improper Restriction of Rendered UI Layers or Frames. This allows attackers to perform clickjacking attacks that can trick victims into performing actions such as entering passwords, liking or deleting posts, an…

[Blink1Control2] Blink1Control2 uses weak password encryption

  • Posted inHIGH
  • Posted byGitHub
  • 09/08/202209/17/2022

The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. Version 2.2.9 fixes the issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-35513
https://github.com/p1ckzi/CVE-2022-35513
https://gith…

[mei2volpiano] MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)

  • Posted inHIGH
  • Posted byGitHub
  • 09/08/202209/17/2022

DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe ‘xml.etree’ library to parse untrusted XML input.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3718…

[francoisjacquet/rosariosis] RosarioSIS before 10.1 vulnerable to Improper Handling of Length Parameter Inconsistency

  • Posted inHIGH
  • Posted byGitHub
  • 09/07/202209/15/2022

RosarioSIS Student Information System prior to version 10.1 is vulnerable to Improper Handling of Length Parameter Inconsistency.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2714
https://github.com/francoisjacquet/rosariosis/commit/4022954c3f…

[barbican] Barbican authorization flaw before v14.0.0

  • Posted inHIGH
  • Posted byGitHub
  • 09/07/202209/15/2022

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the n…

Posts navigation

Previous Posts 1 … 65 66 67 68 69 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close