Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[github.com/lightningnetwork/lnd] Witness Block Parsing DoS Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 11/19/202211/19/2022

Impact
All lnd nodes before version v0.15.4 are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can continue to make payments and forward HTLCs, and close out channels. O…

[github.com/oam-dev/kubevela] List helm chart endpoint of VelaUX APIserver has SSRF vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 11/19/202211/19/2022

Impact
Users using the VelaUX APIServer could be affected by this vulnerability.
When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.
Patches
For users …

[dolibarr/dolibarr] Dolibarr vulnerable to privilege escalation

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/18/202211/22/2022

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43138
https://www.exploit-db.com/exploits/50248
https://github.com/Dolibarr/…

[rdiffweb] Rdiffweb vulnerable to Missing Authentication for Critical Function

  • Posted inMODERATE
  • Posted byGitHub
  • 11/17/202211/29/2022

Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4018
https://github.com/ikus060/rdiffweb/commit/f2a32f2a9f3fb8be1a9432ac3d81d3aacdb13095
https://…

[github.com/hashicorp/consul] Missing Authorization in HashiCorp Consul

  • Posted inHIGH
  • Posted byGitHub
  • 11/16/202211/22/2022

HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering’s imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3920
https://discu…

[org.apache.sshd:sshd-common] Unsafe deserialization in Apache MINA SSHD

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/16/202211/22/2022

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apach…

[wsgidav] Cross Site Scripting vulnerability in wsgidav when directory browsing is enabled

  • Posted inHIGH
  • Posted byGitHub
  • 11/16/202211/17/2022

Impact
Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks.
Patches
Users can upgrade to v4.1.0
Workarounds
Set dir_browser.enable = False in the configuration. For instance, when …

[github.com/russellhaering/gosaml2] gosaml2 is vulnerable to NULL Pointer Dereference

  • Posted inHIGH
  • Posted byGitHub
  • 11/16/202211/16/2022

Impact
In versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference.
Patches
The issue was patched in v0.7.0, released on March 2, 2022.
Workarounds
Callers to g…

[org.apache.archiva:archiva-common] Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user

  • Posted inHIGH
  • Posted byGitHub
  • 11/16/202211/29/2022

Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files. If anonymous read enabled, it’s possible to read the database file directly without logging in.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-40308
https://list…

[org.apache.archiva:archiva-common] Apache Archiva subject to arbitrary directory deletion by users.

  • Posted inMODERATE
  • Posted byGitHub
  • 11/16/202211/22/2022

Apache Archiva prior to 2.2.9 allows an authenticated user to delete arbitrary directories. Users with write permissions to a repository can delete arbitrary directories.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-40309
https://lists.apache….

Posts navigation

Previous Posts 1 … 7 8 9 10 11 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close