Skip to content

トピトピニュース

Header Image

[org.apache.nifi:nifi] Improper Authentication In Apache NiFi

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the “anonymous” user.
References

https://nvd.nist.gov/vuln/detail/…

[com.nimbusds:nimbus-jose-jwt] Nimbus JOSE+JWT vulnerable to padding oracle attack

  • Posted inLOW
  • Posted byGitHub
  • 05/13/202211/09/2022

Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-12973
https://bitbu…

[pyjwt] PyJWT vulnerable to key confusion attacks

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202209/12/2022

In PyJWT 1.5.0 and below the invalid_strings check in HMACAlgorithm.prepare_key does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the string —–BEGIN RSA PUBLIC K…

[puppet] Tarball permission preservation in puppet

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202207/23/2022

When installing a module using the system tar, the PMT will filter filesystem permissions to a sane value. This may just be based on the user’s umask.
When using minitar, files are unpacked with whatever permissions are in the tarball. This is potentia…

[Electron] Electron vulnerable to URL spoofing via PDFium

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202209/16/2022

Electron version 1.7.0 – 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-1000424
https://github.com/electron/ele…

[org.jvnet.hudson.plugins:ssh] Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/23/2022

The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[org.opencastproject:opencast-kernel] Opencast has Incorrect Permission Assignment

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/09/2022

In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access r…

[org.jboss.ws:jbossws-common] JBossWS vulnerable to uncontrolled recursion

  • Posted inLOW
  • Posted byGitHub
  • 05/13/202211/08/2022

DOMUtils.java in org.jboss.ws:jbossws-common does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOC…

[io.undertow:undertow-core] Undertow Request Smuggling vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-12165
https://bugzilla.redhat…

[io.hawt:project] Path Traversal in io.hawt:project

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/05/2022

hawtio before versions 2.0-beta-1, 2.0-beta-2, 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 are vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within…

Posts navigation

Previous Posts 1 … 86,782 86,783 86,784 86,785 86,786 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close