Skip to content

トピトピニュース

Header Image

[io.hawt:project] Insecure cookie sharing in Hawtio

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/05/2022

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy…

[org.jbpm.jbpm5:jbpmmigration] XML External Entity Reference in jbpmmigration

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/05/2022

It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potent…

[io.undertow:undertow-core] Undertow vulnerable to Request Smuggling

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/08/2022

In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be ex…

[io.hawt:project] Cross-Site Request Forgery in hawtio

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/05/2022

It was found that hawtio contains a CSRF flaw that allows unrelated websites to perform actions as the authenticated user. Attackers could use this vulnerability to trick the user to visit his website that contains a malicious script which can be submi…

[org.elasticsearch.plugin:x-pack] Improper Privilege Management in X-Pack

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/05/2022

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another r…

[com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer] Cross-site Scripting in Jenkins Build Failure Analyzer plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/02/2022

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-49…

[com.nimbusds:nimbus-jose-jwt] Nimbus JOSE+JWT missing overflow check

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/09/2022

In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so that different …

[com.typesafe.play:play_2.12] Play Framework’s Assets controller vulnerable to directory traversal

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/23/2022

A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially …

[org.apache.atlas:atlas-common] Cross-site Scripting in Apache Atlas

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/05/2022

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-3151
https://lists.apache.org/thread.html/4a4fef91e067…

[org.richfaces:richfaces] Remote code execution due to insecure deserialization

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/04/2022

A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of securit…

Posts navigation

Previous Posts 1 … 86,783 86,784 86,785 86,786 86,787 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close