Skip to content

トピトピニュース

Header Image

[org.apache.struts:struts2-struts1-plugin] Code execution in Apache Struts 1 plugin

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/04/2022

The Struts 1 plugin used with Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-9791
https://security.netapp.c…

[org.apache.sling:org.apache.sling.xss] Cross site scripting in Apache Sling

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/04/2022

In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags to pass through unencoded, leading to potential XSS vuln…

[org.apache.commons:commons-collections4] Deserialization of Untrusted Data in Apache commons collections

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/04/2022

It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the…

[org.apache.myfaces.core:myfaces-impl] Path Traversal in Apache MyFaces

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/02/2022

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.fa…

[org.vivoweb:vitro-project] Command Injection in VIVO Vitro

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request…

[org.gradle:gradle-core] Insecure transport protocol in Gradle

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/02/2022

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.goo…

[org.apache.orc:orc] Apache ORC vulnerable to Uncontrolled Recursion

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug is most likely denial-of-service against software that uses the ORC file parser. With the C++ parser, t…

[org.richfaces:richfaces-core] Arbitrary code execution in Richfaces

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/08/2022

JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData o…

[org.richfaces:richfaces-core] RichFaces vulnerable to Expression Language Injection

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/08/2022

JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource’s resource request, aka RF-14309.
References

https:/…

[org.jvnet.hudson.plugins:hipchat] Jenkins HipChat Plugin allows credential capture due to incorrect authorization

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/23/2022

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified…

Posts navigation

Previous Posts 1 … 86,784 86,785 86,786 86,787 86,788 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close