Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[kubevirt.io/kubevirt] Duplicate Advisory: KubeVirt arbitrary host file read from the VM

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202209/30/2022

Duplicate Advisory
This advisory is a duplicate of GHSA-qv98-3369-g364. This link is maintained to preserve external references.
Original Description
Summary
As part of a Kubevirt audit performed by NCC group, a finding dealing with systemic lack of pa…

[oqs] oqs’s Post-Quantum Key Encapsulation Mechanism SIKE broken

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202208/19/2022

Wouter Castryck and Thomas Decru presented an efficient key recovery attack on the SIDH protocol.
As a result, the secret key of SIKEp751 can be recovered in a matter of hours.
The SIKE and SIDH schemes will be removed from oqs 0.7.2.
An efficient key …

[notrinos/notrinos-erp] NotrinosERP Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 08/18/202208/31/2022

NotrinosERP version 0.7 and prior is vulnerable to stored cross-site scripting. A fix is available on the master branch of the repository.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2871
https://github.com/notrinos/notrinoserp/commit/0362778…

[github.com/hashicorp/consul] HashiCorp Consul Template could reveal Vault secret contents in error messages

  • Posted inHIGH
  • Posted byGitHub
  • 08/18/202209/08/2022

In HashiCorp Consul Template through version 0.29.1, invalid templates could inadvertently reveal the contents of Vault secret in errors returned by the *template.Template.Execute 5 method, when given a template using Vault secret contents incorrectly….

[@mapbox/mapbox-maps-android] Mapbox is vulnerable to Integer Overflow

  • Posted inHIGH
  • Posted byGitHub
  • 08/17/202211/22/2022

An integer overflow exists in Mapbox’s closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating …

[rocksdb] rocksdb vulnerable to out-of-bounds read

  • Posted inMODERATE
  • Posted byGitHub
  • 08/13/202208/13/2022

Affected versions of this crate called the RocksDB C API
rocksdb_open_column_families_with_ttl() with a pointer to a single integer
TTL value, but one TTL value for each column family is expected.
This is only relevant when using
rocksdb::DBWithThreadM…

[update_by_case] update_by_case before 0.1.3 can be vulnerable to sql injection

  • Posted inMODERATE
  • Posted byGitHub
  • 08/12/202208/23/2022

Before version 0.1.3 update_by_case gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >= 0.1.3 that uses Arel instead to construct the resulting sql statement, with sanitized sql.
Refere…

[temporary] `temporary` makes use of uninitialized memory

  • Posted inMODERATE
  • Posted byGitHub
  • 08/12/202208/12/2022

Uninit memory is used as a RNG seed in temporary. This has been resolved in the 0.6.4 release. The crate is not intended to be used outside of a testing environment. For a general purpose crate to create temporary directories, tempfile is an alternativ…

[tower-http] tower-http’s improper validation of Windows paths could lead to directory traversal attack

  • Posted inHIGH
  • Posted byGitHub
  • 08/12/2022

tower_http::services::fs::ServeDir didn’t correctly validate Windows paths, meaning paths like /foo/bar/c:/windows/web/screen/img101.png would be allowed and respond with the contents of c:/windows/web/screen/img101.png. Thus users could potentially re…

[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths

  • Posted inMODERATE
  • Posted byGitHub
  • 08/11/202208/24/2022

Cross-linking to https://github.com/jupyter/nbviewer/security/advisories/GHSA-h274-fcvj-h2wm
Most of the fixes will be in this repo, though, so having it here gives us the private fork to work on patches
Below is currently a duplicate of the original r…

Posts navigation

Previous Posts 1 … 75 76 77 78 79 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close