Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[io.undertow:undertow-core] Undertow Request Smuggling vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-12165
https://bugzilla.redhat…

[io.hawt:project] Insecure cookie sharing in Hawtio

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/05/2022

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy…

[io.hawt:project] Path Traversal in io.hawt:project

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/05/2022

hawtio before versions 2.0-beta-1, 2.0-beta-2, 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 are vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within…

[org.jbpm.jbpm5:jbpmmigration] XML External Entity Reference in jbpmmigration

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/05/2022

It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potent…

[io.hawt:project] Cross-Site Request Forgery in hawtio

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/05/2022

It was found that hawtio contains a CSRF flaw that allows unrelated websites to perform actions as the authenticated user. Attackers could use this vulnerability to trick the user to visit his website that contains a malicious script which can be submi…

[io.undertow:undertow-core] Undertow vulnerable to Request Smuggling

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/08/2022

In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be ex…

[org.elasticsearch.plugin:x-pack] Improper Privilege Management in X-Pack

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/05/2022

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another r…

[com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer] Cross-site Scripting in Jenkins Build Failure Analyzer plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/02/2022

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-49…

[com.nimbusds:nimbus-jose-jwt] Nimbus JOSE+JWT missing overflow check

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/09/2022

In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so that different …

[com.typesafe.play:play_2.12] Play Framework’s Assets controller vulnerable to directory traversal

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/23/2022

A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially …

Posts navigation

Previous Posts 1 … 97 98 99 100 101 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close