Skip to content

トピトピニュース

Header Image

[org.elasticsearch:elasticsearch] Cross-site scripting in Elasticsearch

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-6439
ht…

[org.apache.struts:struts2-core] Cross-Site Request Forgery in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-7809
http://packetstormsecurity.com/f…

[org.apache.shiro:shiro-web] Improper Access Control in Apache Shiro

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/05/2022

Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-6802
https://github.com/apache/shiro/commit/b15ab9…

[org.jboss.resteasy:resteasy-bom] JBoss RESTEasy vulnerable to Improper Input Validation

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/23/2022

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
Refere…

[struts:struts] Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cook…

[org.apache.cayenne:cayenne-parent] XML External Entity Reference in Apache Cayenne

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/05/2022

This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models stored as XML files. If an attacker t…

[org.apache.struts:struts2-core] Cross-site Scripting in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

When the Struts2 debug mode is turned on, under certain conditions an arbitrary script may be executed in the ‘Problem Report’ screen. Also if JSP files are exposed to be accessed directly it’s possible to execute an arbitrary script.
It is generally …

[org.apache.struts:struts2-core] Arbitrary code execution in Apache Struts 2

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/04/2022

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
References

https://nvd…

[org.apache.struts:struts2-core] Cross-site Scripting in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte cha…

[org.apache.struts:struts2-core] Arbitrary code execution in Apache Struts 2

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/04/2022

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both “${}” and “%{}” sequences, which causes the OGNL code to be evaluated twice.
References

https://nvd.nist.gov/v…

Posts navigation

Previous Posts 1 … 86,777 86,778 86,779 86,780 86,781 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close