Skip to content

トピトピニュース

Header Image

[org.graylog2:graylog2-server] Cross-site Scripting in Graylog Server

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/05/2022

Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-11650
https://github.com/Graylog2/graylog2-server/pull/4727
http…

[org.graylog2:graylog2-server] Cross-site Scripting in Graylog

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/05/2022

Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
References

https://nvd.nist.gov/vuln/d…

[org.apache.struts:struts2-core] Special top object can be used to access Struts’ internals

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/04/2022

ValueStack defines special top object which represents root of execution context. It can be used to manipulate Struts’ internals or can be used to affect container’s settings. Applying better regex which includes pattern to exclude request parameters t…

[org.apache.struts:struts2-core] Possible DoS attack when using URLValidator

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
References

https://nvd.nist.gov/vuln/…

[org.jvnet.hudson.plugins:groovy-postbuild] Jenkins Groovy Postbuild Plugin vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/23/2022

A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user’s brow…

[org.csanchez.jenkins.plugins:kubernetes] Exposure of Sensitive Information in Jenkins Kubernetes Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.
References

https://nvd.nist.gov/vuln/deta…

[net.opentsdb:opentsdb] OpenTSDB Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/23/2022

An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter json to the /q URI.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-12973
https://github.com/OpenTSDB/opentsdb/issues/1240
https://github.com/advisories/GHSA-r68m-wq3x-2hqw

[io.jenkins:configuration-as-code] Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/09/2022

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration. Ve…

[com.amazonaws:codedeploy] Jenkins AWS CodeDeploy Plugin has Insufficiently Protected Credentials

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/08/2022

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to…

[org.graylog2:graylog2-server] Cross-site Scripting in Graylog Server

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/05/2022

In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-14380
https://github.com/Graylog2/graylog2-ser…

Posts navigation

Previous Posts 1 … 86,776 86,777 86,778 86,779 86,780 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close