Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[golang.org/x/crypto/ssh] x/crypto/ssh vulnerable to panic via SSH server

  • Posted inHIGH
  • Posted byGitHub
  • 09/07/202209/17/2022

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-43565
https://groups.google.com/forum/#!forum/golang-announce
http…

[feehi/cms] FeehiCMS has an arbitrary file upload vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/07/202209/16/2022

There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8.1 at the head image upload, that allows attackers to execute relevant PHP code.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-21516
https://github.com/liufee/cms/issues/46
https:…

[org.gluu:oxauth-common] Gluu Oxauth before v4.4.1 vulnerable to Server-Side Request Forgery attacks via a crafted request_uri parameter

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/07/202209/17/2022

Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-36663
https://github.com/GluuFederation/oxAuth/releases/ta…

[org.yaml:snakeyaml] snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds Write

  • Posted inMODERATE
  • Posted byGitHub
  • 09/06/202209/14/2022

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DoS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.
References

https://n…

[org.yaml:snakeyaml] snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write

  • Posted inMODERATE
  • Posted byGitHub
  • 09/06/202209/15/2022

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
References

https://nv…

[org.apache.iotdb:iotdb-grafana-connector] Apache IoTDB grafana-connector contains an interface without authorization

  • Posted inHIGH
  • Posted byGitHub
  • 09/06/202209/15/2022

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of a database. Users should upgrade to version 0.13.1, which addresses this issue.
References

https://nvd.nist.gov/vuln/…

[org.yaml:snakeyaml] snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write

  • Posted inMODERATE
  • Posted byGitHub
  • 09/06/202209/17/2022

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
References

https://nv…

[org.yaml:snakeyaml] snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write

  • Posted inMODERATE
  • Posted byGitHub
  • 09/06/202209/17/2022

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
References

https://nv…

[apache-airflow] Apache Airflow Session Fixation vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/03/202209/15/2022

In Apache Airflow versions 2.2.4 through 2.3.3, the database webserver session backend was susceptible to session fixation.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38054
https://lists.apache.org/thread/rsd3h89xdp16rg0ltovx3m7q3ypkxsbb
htt…

[apache-airflow] Apache Airflow exposes arbitrary file content

  • Posted inMODERATE
  • Posted byGitHub
  • 09/03/202209/17/2022

In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the –daemon flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local u…

Posts navigation

Previous Posts 1 … 66 67 68 69 70 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close