Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[kiwitcms] Cross-site Scripting in kiwitcms

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/24/2022

A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.
References

https://nvd.nist….

[backdrop/backdrop] Cross-site Scripting in Backdrop CMS

  • Posted inLOW
  • Posted byGitHub
  • 11/22/202211/22/2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content. The account must have admin privileges.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-42096
https://github.com/backdrop/ba…

[tensorflow] `MirrorPadGrad` heap out of bounds read

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/22/2022

Impact
If MirrorPadGrad is given outsize input paddings, TensorFlow will give a heap OOB error.
import tensorflow as tf
tf.raw_ops.MirrorPadGrad(input=[1],
paddings=[[0x77f00000,0xa000000]],
mode = ‘REFLECT’)

Patches
We have …

[tflite] Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite

  • Posted inHIGH
  • Posted byGitHub
  • 11/22/2022

Impact
The reference kernel of the CONV_3D_TRANSPOSE TensorFlow Lite operator wrongly increments the data_ptr when adding the bias to the result.
Instead of data_ptr += num_channels; it should be data_ptr += output_num_channels; as if the number of inp…

[tensorflow] `CHECK_EQ` fail in `tf.raw_ops.TensorListResize`

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/2022

Impact
If tf.raw_ops.TensorListResize is given a nonscalar value for input size, it results CHECK fail which can be used to trigger a denial of service attack.
import numpy as np
import tensorflow as tf

a = data_structures.tf_tensor_list_new(elements …

[aliyun-oss-client] Leakage Aliyun KeySecret

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/29/2022

Impact
Users of this library will be affected when using this library, the incoming secret will be disclosed unintentionally.
Patches
This have already been solved.
Workarounds
No, It cannot be patched without upgrading
References
No
For more informati…

[github.com/codenotary/immudb/pkg/client] Lack of proper validation of server UUID can be used by the server to trick the client to accept invalid proofs

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/29/2022

Impact
immudb client SDKs use server’s UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. SDK does not validate this uuid and can accept any value …

[github.com/codenotary/immudb/pkg/client] Insufficient Verification of Proofs generated by the immudb server in client SDK.

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/29/2022

Impact
In certain scenario a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and req…

[org.apache.hama:hama-core] Cross-site Scripting in Apache Hama

  • Posted inMODERATE
  • Posted byGitHub
  • 11/22/202211/22/2022

Missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-45470
https://lists.apac…

[org.bouncycastle:bc-fips] Garbage collection issue in BC-FJA in Java 13 and later

  • Posted inMODERATE
  • Posted byGitHub
  • 11/21/202211/22/2022

An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be …

Posts navigation

Previous Posts 1 … 5 6 7 8 9 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close