Skip to content

トピトピニュース

Header Image

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3152
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa…

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3155
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa65e2a0520acde71d…

[org.apache.atlas:atlas-common] Apache Atlas produces Stack trace in error response

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/05/2022

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3154
https://lists.apache.org/thread.html/4a4fef91e067fd0d9da56…

[scrapy] Scrapy denial of service vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/08/2022

Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files are then individually written in a separate thread to…

[org.apache.struts:struts2-core] Incomplete exclude pattern in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/04/2022

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to “compromise internal state of an application” via unspecified vectors. In Struts 2.3.20.1 a better set of exlude patterns was defined.
References

https://nv…

[org.apache.geode:geode-core] Apache Geode gfsh query vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/08/2022

When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user’s concurrentl…

[mistune] Cross-site Scripting in Mistune

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202209/09/2022

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-15612
https://github.com/lepture…

[com.neovisionaries:nv-websocket-client] nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/08/2022

The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS s…

[io.undertow:undertow-core] Undertow Uncaught Exception vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/08/2022

A long URL proxy request lead to java.nio.BufferOverflowException in Undertow.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-7046
https://bugzilla.redhat.com/show_bug.cgi?id=1376646
https://github.com/undertow-io/undertow/commit/c518b5a1784061d…

バットマン亡き後のゴッサム・シティを描く「ゴッサム・ナイツ」が2022年10月25日(火)に発売決定!

  • Posted inUncategorized
  • Posted byFunglr Games(日本語)
  • 05/14/2022

ゴッサム・シティを舞台にした新作オープンワールドアクションRPG「ゴッサム・ナイツ」当初は2021年…

Posts navigation

Previous Posts 1 … 86,773 86,774 86,775 86,776 86,777 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close