Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[org.eclipse.xtext:org.eclipse.xtext] Potentially compromised builds

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/05/2022

All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-10249
https://github.com/eclipse/xtext-xte…

[org.apache.portals.pluto:chatRoomDemo] Cross-site Scripting in Apache Pluto Chatroom demo

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/04/2022

The input fields of the Apache Pluto “Chat Room” demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file – or – * migrate to version 3.1.0 of the chat-room-demo war file
Refer…

[org.apache.qpid:proton-j] Improper Certificate Validation in Apache Qpid Proton

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/02/2022

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS even when configured to verify the peer certifi…

[org.eclipse.vorto:org.eclipse.vorto.core] Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/23/2022

Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto mig…

[org.jenkins-ci.plugins:ontrack] Sandbox bypass in ontrack Jenkins Plugin

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/09/2022

A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbitrary code on the Jenkins master JVM.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-10306
https:…

[octoprint] Cross-site Scripting in OctoPrint

  • Posted inHIGH
  • Posted byGitHub
  • 05/19/202209/09/2022

Cross-site Scripting (XSS) – Generic in GitHub repository octoprint/octoprint prior to 1.8.0. The Stream URL of octoprint application allowing a xss payload to execute.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-1432
https://github.com/octop…

[DotNetCasClient] Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/18/202211/23/2022

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrar…

[org.apache.struts:struts2-core] Cross-site Scripting in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/04/2022

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.
References

…

[org.apache.struts:struts2-core] Broken Access Control Vulnerability in Apache Struts2

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/04/2022

The Struts 2 action mapping mechanism supports the special parameter prefix action: which is intended to help with attaching navigational information to buttons within forms, under certain conditions this can be used to bypass security constraints.
In…

[org.apache.portals.jetspeed-2:jetspeed] Path Traversal in Apache Jetspeed

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/04/2022

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot do…

Posts navigation

Previous Posts 1 … 85 86 87 88 89 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close