Skip to content

トピトピニュース

Header Image
Category

HIGH

381 Posts

Featured

Posted byGitHub
[phpxmlrpc/phpxmlrpc] code injection in phpxmlrpc/phpxmlrpc
Posted byGitHub
[ghost] ghost vulnerable to unauthorized newsletter modification via improper access controls
Posted byGitHub
[microweber/microweber] Account Takeover Through Password Reset Poisoning
Posted byGitHub
[apache-airflow] OS Command Injection in Apache Airflow

[org.apache.iotdb:iotdb-grafana-connector] Apache IoTDB grafana-connector contains an interface without authorization

  • Posted inHIGH
  • Posted byGitHub
  • 09/06/202209/15/2022

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of a database. Users should upgrade to version 0.13.1, which addresses this issue.
References

https://nvd.nist.gov/vuln/…

[os_socketaddr] `os_socketaddr` invalidly assumes the memory layout of std::net::SocketAddr

  • Posted inHIGH
  • Posted byGitHub
  • 09/03/2022

The os_socketaddr crate has assumed std::net::SocketAddrV4 and std::net::SocketAddrV6 have the same memory layout as the system C representation sockaddr. It has simply casted the pointers to convert the socket addresses to the system representation.
T…

[org.apache.shenyu:shenyu-common] Apache ShenYu Admin v2.4.2-v2.4.3 has insecure permissions

  • Posted inHIGH
  • Posted byGitHub
  • 09/02/202209/15/2022

Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator’s passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3. Version 2.5.0 contains a patch for this issue.
References

…

[python-scciclient] python-scciclient vulnerable to Man-in-the-middle (MITM) attacks

  • Posted inHIGH
  • Posted byGitHub
  • 09/02/202209/17/2022

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server’s certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
References

https://nvd.nist.go…

[github.com/ElrondNetwork/elrond-go] elrond-go MultiESDTNFTTransfer call on a SC address with missing function name

  • Posted inHIGH
  • Posted byGitHub
  • 09/02/202209/10/2022

Impact
Anyone who uses elrond-go to process blocks (historical or actual) that contains a transaction like this: MultiESDTNFTTransfer@01@54444558544b4b5955532d323631626138@00@0793afc18c8da2ca@ (mind the missing function name after the last @)
Basic fun…

[github.com/fluxcd/flux2] Flux CLI Workload Injection

  • Posted inHIGH
  • Posted byGitHub
  • 09/02/202209/02/2022

Flux CLI allows users to deploy Flux components into a Kubernetes cluster via command-line. The vulnerability allows other applications to replace the Flux deployment information with arbitrary content which is deployed into the target Kubernetes clust…

[org.apache.geode:geode-core] Apache Geode versions deserialization of untrusted datawhen using JMX over RMI on Java 11

  • Posted inHIGH
  • Posted byGitHub
  • 09/01/202209/17/2022

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode…

[nitrado.js] Polynomial regular expression used on uncontrolled data in nitrado.js

  • Posted inHIGH
  • Posted byGitHub
  • 09/01/202209/08/2022

Impact
Possible ReDoS with lib input of {{ and with many repetitions of {{|
Patches
Patched in all versions above 0.2.5
Workarounds
No known work arounds.
References

OWASP: Regular expression Denial of Service – ReDoS
Wikipedia: ReDoS.
Wikipedia: Time…

[matrix-synapse] Denial of service due to incorrect application of event authorization rules

  • Posted inHIGH
  • Posted byGitHub
  • 09/01/202209/10/2022

Impact
The Matrix specification specifies a list of event authorization rules which must be checked when determining if an event should be accepted into a room.
In versions of Synapse up to and including v1.61, some of these rules are not correctly app…

[org.yaml:snakeyaml] Uncontrolled Resource Consumption in snakeyaml

  • Posted inHIGH
  • Posted byGitHub
  • 08/31/202209/10/2022

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-25857
https://github.com/snakeyaml/snakeyaml/c…

Posts navigation

Previous Posts 1 … 20 21 22 23 24 … 39 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close