Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[jenkins.xtc:extensivetesting] Cleartext Storage of Sensitive Information in Jenkins Extensive Testing Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/02/2022

Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
References

https://nvd.nist.gov/vuln/de…

[org.glassfish:javax.faces] Cross-site Scripting in Eclipse Mojarra

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/04/2022

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces, allows Reflected XSS because a client window field is mishandled.
References

https://nvd.nist.gov/vuln/detail…

[io.fabric8.pipeline:kubernetes-pipeline-steps] Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/09/2022

Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-10…

[io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps] Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/09/2022

Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-10…

[org.apereo.cas:cas-server-support-simple-mfa] Use of Insufficiently Random Values in Apereo CAS

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/02/2022

Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG’s algorithm not being cryptographically strong.
…

[org.apache.jspwiki:jspwiki-main] Cross-site Scripting in Apache JSPWiki

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/05/2022

In Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in …

[org.gradle:gradle-core] Use of a weak cryptographic algorithm in Gradle

  • Posted inLOW
  • Posted byGitHub
  • 05/25/202211/02/2022

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
References

https://nvd.nist….

[kevinpapst/kimai2] Kimai v2 is vulnerable to Cross-Site Scripting (XSS)

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202209/13/2022

Kimai v2 before 1.1 has XSS via a timesheet description.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-15481
https://github.com/kevinpapst/kimai2/pull/962
https://github.com/kevinpapst/kimai2/releases/tag/1.1
https://github.com/advisories/GHSA-…

[org.apache.storm:storm-core] Exposure of Sensitive Information in Apache Storm Logviewer

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/05/2022

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host’s file system that were not intended to b…

[org.apache.karaf.config:org.apache.karaf.config.core] Apache Karaf vulnerable to relative path traversal

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/17/2022

Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apa…

Posts navigation

Previous Posts 1 … 84 85 86 87 88 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close