Skip to content

トピトピニュース

Header Image

[org.apache.struts:struts2-core] Code injection in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/04/2022

Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2013-4316
http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.html
…

[org.jruby:jruby] Ruby vulnerable to denial of service

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/08/2022

When reading text nodes from an XML document, the REXML parser can be coerced in to allocating extremely large string objects which can consume all of the memory on a machine, causing a denial of service.
Jruby resolves this bug in version 1.7.3 as not…

[org.apache.geode:geode-core] Apache Geode information disclosure vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/08/2022

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute …

[org.apache.sling:org.apache.sling.xss] XML External Entity Reference in Apache Sling

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/17/202211/04/2022

In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially…

[org.apache.struts:struts2-core] Possible DoS attack when using URLValidator

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/04/2022

The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-4465
https://bugzilla….

[org.apache.struts:struts2-core] Cross-Site Request Forgery in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/04/2022

The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration…

[org.apache.struts:struts2-core] Denial of service in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/04/2022

Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
References

https://nvd.nist.gov/vuln/detail/CVE-2012-4387
https://exchange.xf…

[org.apache.atlas:atlas-common] Insecure cookie storage in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3150
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa65e2…

[org.apache.atlas:atlas-common] Path Traversal in Apache Atlas

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-8752
https://lists.apache.or…

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3153
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867…

Posts navigation

Previous Posts 1 … 86,772 86,773 86,774 86,775 86,776 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close