Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[org.apache.atlas:atlas-common] Insecure cookie storage in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3150
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa65e2…

[org.apache.atlas:atlas-common] Path Traversal in Apache Atlas

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-8752
https://lists.apache.or…

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3152
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa…

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3153
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867…

[org.apache.atlas:atlas-common] Apache Atlas produces Stack trace in error response

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/05/2022

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3154
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da56…

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3155
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa65e2a0520acde71d…

[scrapy] Scrapy denial of service vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/08/2022

Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files are then individually written in a separate thread to…

[org.apache.struts:struts2-core] Incomplete exclude pattern in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/04/2022

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to “compromise internal state of an application” via unspecified vectors. In Struts 2.3.20.1 a better set of exlude patterns was defined.
References

https://nv…

[org.apache.geode:geode-core] Apache Geode gfsh query vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/08/2022

When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user’s concurrentl…

[mistune] Cross-site Scripting in Mistune

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202209/09/2022

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-15612
https://github.com/lepture…

Posts navigation

Previous Posts 1 … 87 88 89 90 91 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close