Skip to content

トピトピニュース

Header Image

[bootstrap] Bootstrap vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202209/20/2022

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-14040
https://github.com/twbs/bootstrap/issues/26423
https://github.com/twbs/bootstrap/issues/26625
https://github.c…

[Microsoft.NETCore.Jit] .NET Core Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202210/26/2022

.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka “.NET Core Denial of Service Vulnerability”.
References

https://nvd.nist.gov/vuln/detai…

[org.jenkins-ci.main:jenkins-core] Improper Authorization in Jenkins Core

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefin…

[org.jenkins-ci.main:jenkins-core] Improper Authorization in Jenkins Core

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me …

[org.apache.mesos:mesos] Docker image code execution with Apache Mesos

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1…

[org.springframework.data:spring-data-rest-core] Remote code execution in PATCH requests in Spring Data REST

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/05/2022

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) can use specially crafted JSON data to run arbitrary Java code.
References

https://nvd.nist.gov/vuln/detail/C…

[org.apache.deltaspike.modules:jsf-module-project] Cross-site Scripting in Apache DeltaSpike

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/04/2022

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get’s cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspi…

ゲーミングPC200台!大型LEDを完備した国内最大級の教育eスポーツ施設が誕生!オープンキャンパスのほか、高校eスポーツ部活動支援事業も!

  • Posted inUncategorized
  • Posted byFunglr Games(日本語)
  • 05/12/2022

ゲーミングPC200台と大型LEDを完備。752.7m2を誇る教育機関として国内最大クラスのeスポー…

ハーレー新型ナイトスターの詳細や特徴と試乗レビュー

  • Posted inUncategorized
  • Posted byバイクウーマン
  • 05/12/2022

いよいよ発売されました、新型ナイトスターですが、第一印象がめちゃくちゃかっこいいですよね! 特にパッ…

Google I/O 2022 Keynote: Android開発者まとめ

  • Posted inAndroid
  • Posted byMhidaka
  • 05/12/2022

2022年5月12日(現地時刻)Google I/O 2022 Keynote およびDeveloper KeynoteよりAndroid関連のトピックをお届けします。今年のGoogle I/Oも基本的にはオンラインイベ […]

The post Google I/O 2022 Keynote: Android開発者まとめ first appeared on TechBooster.

Posts navigation

Previous Posts 1 … 86,786 86,787 86,788 86,789 86,790 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close