Skip to content

トピトピニュース

Header Image

[org.apache.struts:struts2-core] ClassLoader manipulation in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/04/2022

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to “manipulate” the ClassLoader and execute arbitrary code via a crafte…

[org.apache.struts:struts2-core] Arbitrary code execution in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/04/2022

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
References

https://nvd.nist.gov/vuln/detail/C…

[org.apache.struts:struts2-core] ClassLoader manipulation in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to “manipulate” the ClassLoader via the class parameter, which is passed to the getClass method.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-0094
http://jvn.jp…

[org.apache.struts:struts2-core] ClassLoader manipulation in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/04/2022

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to “manipulate” the ClassLoader and modify session state via a craf…

[org.apache.struts:struts2-core] Path Traversal in Apache Struts

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/14/202211/04/2022

In Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side. This vulnerability is only exploitable when using the Struts 2 C…

[org.apache.struts:struts2-core] Arbitrary code execution in Apache Struts 2

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/14/202211/04/2022

The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-4438
https://bugzilla.redhat.com/show_bug.cgi?id=1348238
https:…

[org.apache.santuario:xmlsec] Apache XML Security For Java vulnerable to Infinite Loop

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/08/2022

Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method expandSize(int newPos) of class org.apache.xml.security.utils.UnsyncByteArrayOutputStream goes i…

[org.csanchez.jenkins.plugins:kubernetes] Exposure of Sensitive Information in Jenkins Kubernetes Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/04/2022

An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
References

https://nvd.nist.g…

[org.jenkins-ci.main:jenkins-core] Infinite Loop in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/02/2022

A Cron expression form validation could enter infinite loop, potentially resulting in denial of service. The form validation for cron expressions (e.g. “Poll SCM”, “Build periodically”) could enter infinite loops when cron expressions only matching cer…

[org.apache.guacamole:guacamole-common] Missing Encryption of Sensitive Data in Apache Guacamole

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/04/2022

Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user’s session token. This cookie lacked the “secure” flag, which could allow an attacker eavesdropping on the network to intercept the user’s session token if unencrypted HT…

Posts navigation

Previous Posts 1 … 86,780 86,781 86,782 86,783 86,784 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close