Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[librenms] LibreNMS vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 08/31/202209/17/2022

LibreNMS version 22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-36746
https://github.com/librenms/librenms/pull/14126
https…

[librenms] LibreNMS vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 08/31/202209/27/2022

LibreNMS version 22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-36745
https://github.com/librenms/librenms/pull/14126
https://comm…

[github.com/zitadel/zitadel] Broken Authorization in ZITADEL Actions

  • Posted inHIGH
  • Posted byGitHub
  • 08/31/202209/10/2022

Impact
Actions, introduced in ZITADEL 1.42.0 on the API and 1.56.0 for Console, is a feature, where users with role ORG_OWNER are able to create Javascript Code, which is invoked by the system at certain points during the login.
Actions, for example, a…

[strapi-plugin-ezforms] Captcha Bypass in strapi-plugin-ezforms

  • Posted inMODERATE
  • Posted byGitHub
  • 08/31/202208/31/2022

Impact
Users using any captcha providers
Patches

0.1.0

References
Issue
References

https://github.com/excl-networks/strapi-plugin-ezforms/security/advisories/GHSA-8mgq-6r2q-82w9
https://github.com/excl-networks/strapi-plugin-ezforms/issues/15
https:…

[getkirby/cms] Cross-site scripting from content entered in the tags and multiselect fields

  • Posted inHIGH
  • Posted byGitHub
  • 08/31/202208/31/2022

Introduction
Cross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby’s API wi…

[helm.sh/helm/v3] Denial of service through string value parsing

  • Posted inMODERATE
  • Posted byGitHub
  • 08/31/202209/09/2022

Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause an out of memory panic. Out of memory panics cannot be recovered from. Applications that use functions from the strvals package i…

[github.com/cilium/cilium] Network Policies & (Clusterwide) Cilium Network Policies with namespace label selectors may unexpectedly select pods with maliciously crafted labels

  • Posted inMODERATE
  • Posted byGitHub
  • 08/31/2022

Impact
If a user has Network Policies with namespace selectors selecting labels of namespaces, or (clusterwide) Cilium Network Policies matching on namespace labels, then it is possible for an attacker with Kubernetes pod deploy rights (either directly…

[iana-time-zone] iana-time-zone vulnerable to use after free in MacOS / iOS implementation

  • Posted inMODERATE
  • Posted byGitHub
  • 08/31/202208/31/2022

In iana-time-zone v0.1.43 a use-after-free bug in the MacOS / iOS implementation was introduced.
The copied system time zone was released before its name was copied.
If the system time zone was changed between the call of CFRelease and str::to_owned(),…

[mz-avro] mz-avro’s incorrect use of `set_len` allows for un-initialized memory

  • Posted inMODERATE
  • Posted byGitHub
  • 08/31/202208/31/2022

Affected versions of this crate passes an uninitialized buffer to a user-provided Read
implementation.
Arbitrary Read implementations can read from the uninitialized buffer (memory exposure)
and also can return incorrect number of bytes written to the…

[Microsoft.AspNetCore.App.Runtime.linux-musl-arm] .NET Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 08/31/202208/31/2022

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability…

Posts navigation

Previous Posts 1 … 69 70 71 72 73 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close