Skip to content

トピトピニュース

Header Image
Category

CRITICAL

187 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.jeecgframework.boot:jeecg-boot-common] Jeecg-boot vulnerable to SQL Injection
Posted byGitHub
[electron] Heap buffer overflow in GPU
Posted byGitHub
[wger] wger vulnerable to brute force attempts

[k8s.io/kubernetes] Privilege Escalation

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202109/08/2022

Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-100005…

[org.odata4j:odata4j-dist] SQL Injection in odata4j

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/08/202111/18/2022

odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE, this product is apparently discontinued.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-11023
https://groups.google.com/d/msg/odata4j-discuss/_lBwwXP30g0/Av6zkZMdBwAJ
https:…

[org.odata4j:odata4j-dist] SQL Injection in odata4j

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/08/202111/18/2022

odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE, this product is apparently discontinued.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-11023
https://groups.google.com/d/msg/odata4j-discuss/_lBwwXP30g0/Av6zkZMdBwAJ
https:…

[org.odata4j:odata4j-dist] SQL Injection in odata4j

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/08/202111/18/2022

odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-11024
https://groups.google.com/d/msg/odata4j-discuss/_lBwwXP30g0/Av6zkZMdBwAJ
https:/…

[org.webjars.bowergithub.wycats:handlebars.js] Remote code execution in handlebars when compiling templates

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/07/202110/05/2022

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-23369
https://github….

[clickhouse-driver] Arbitrary code execution in clickhouse-driver

  • Posted inCRITICAL
  • Posted byGitHub
  • 04/08/202111/09/2022

clickhouse-driver before 0.1.5 allows a malicious clickhouse server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, due to a buffer overflow.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-26759…

[lita-coin] Backdoor / Malicious code

  • Posted inCRITICAL
  • Posted byGitHub
  • 02/24/202108/13/2022

lita-coin 0.0.3 contains a backdoor mechanism that allows launching of hidden cryptocurrency mining operations inside the project. The code also contained a backdoor mechanism that allowed the attacker to send a cookie file back to a compromised projec…

[require-node] Arbitrary Code Execution in require-node

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/04/202010/05/2022

Versions of require-node prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to the require-node endpoint, allowing attackers to execute arbitrary code in the server through the in…

[flood] Server secret was included in static assets and served to clients

  • Posted inCRITICAL
  • Posted byGitHub
  • 08/27/202009/10/2022

Impact
Server JWT signing secret was included in static assets and served to clients.
This ALLOWS Flood’s builtin authentication to be bypassed. Given Flood is granted access to rTorrent’s SCGI interface (which is unprotected and ALLOWS arbitrary code …

[mongoose] Improper Input Validation in Automattic Mongoose

  • Posted inCRITICAL
  • Posted byGitHub
  • 10/23/201910/21/2022

Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding “_bsontype”:”a” can sometimes interfere with a query filter. NOTE: th…

Posts navigation

Previous Posts 1 … 16 17 18 19 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close