Skip to content

トピトピニュース

Header Image

新型iPad miniには「Face ID」が搭載されないかも…

  • Posted inUncategorized
  • Posted byUbergizmo Japan
  • 01/28/2019

昨年発売された新型iPad Proには、iPhoneで先行していたFace ID技術が搭載されました…

[org.exist-db:exist-core] exist-db:exist-core XML External Entity (XXE) vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 12/21/201811/16/2022

exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
References

https://nvd.nist.gov/vuln/detail/CVE-…

[org.springframework.security:spring-security-oauth2-jose] Spring Security vulnerable to Authorization Bypass

  • Posted inHIGH
  • Posted byGitHub
  • 12/21/201811/18/2022

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that ca…

[org.springframework.security:spring-security-oauth2-jose] Spring Security vulnerable to Authorization Bypass

  • Posted inHIGH
  • Posted byGitHub
  • 12/21/201811/18/2022

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that ca…

[flatmap-stream] Critical severity vulnerability that affects event-stream and flatmap-stream

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/27/201809/08/2022

The NPM package flatmap-stream is considered malicious. A malicious actor added this package as a dependency to the NPM event-stream package in version 3.3.6. Users of event-stream are encouraged to downgrade to the last non-malicious version, 3.3.4,…

[org.eclipse.jetty:jetty-server] Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/20/201810/06/2022

Eclipse Jetty Server versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), are vulnerable to HTTP Request Smuggling when presented with two content-lengths headers, allowing authorization bypass. Wh…

[org.apache.struts:struts2-core] Apache Struts vulnerable to remote command execution (RCE) due to improper input validation

  • Posted inHIGH
  • Posted byGitHub
  • 10/19/201810/05/2022

Apache Struts contains a Remote Code Execution when using results with no namespace and it’s upper actions have no or wildcard namespace. The same flaw exists when using a url tag with no value, action set, and it’s upper actions have no or wildcard n…

[org.springframework:spring-core] Files or Directories Accessible to External Parties in org.springframework:spring-core

  • Posted inHIGH
  • Posted byGitHub
  • 10/18/201810/05/2022

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script …

[org.springframework:spring-core] Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass

  • Posted inHIGH
  • Posted byGitHub
  • 10/18/201811/18/2022

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
…

[org.springframework:spring-core] Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass

  • Posted inHIGH
  • Posted byGitHub
  • 10/18/201811/18/2022

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
…

Posts navigation

Previous Posts 1 … 86,824 86,825 86,826 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close