Skip to content

トピトピニュース

Header Image
Category

HIGH

381 Posts

Featured

Posted byGitHub
[phpxmlrpc/phpxmlrpc] code injection in phpxmlrpc/phpxmlrpc
Posted byGitHub
[ghost] ghost vulnerable to unauthorized newsletter modification via improper access controls
Posted byGitHub
[microweber/microweber] Account Takeover Through Password Reset Poisoning
Posted byGitHub
[apache-airflow] OS Command Injection in Apache Airflow

[org.apache.nifi:nifi] Improper Authentication In Apache NiFi

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the “anonymous” user.
References

https://nvd.nist.gov/vuln/detail/…

[pyjwt] PyJWT vulnerable to key confusion attacks

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202209/12/2022

In PyJWT 1.5.0 and below the invalid_strings check in HMACAlgorithm.prepare_key does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the string —–BEGIN RSA PUBLIC K…

[io.undertow:undertow-core] Undertow Request Smuggling vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-12165
https://bugzilla.redhat…

[io.hawt:project] Path Traversal in io.hawt:project

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/05/2022

hawtio before versions 2.0-beta-1, 2.0-beta-2, 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 are vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within…

[io.hawt:project] Cross-Site Request Forgery in hawtio

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/05/2022

It was found that hawtio contains a CSRF flaw that allows unrelated websites to perform actions as the authenticated user. Attackers could use this vulnerability to trick the user to visit his website that contains a malicious script which can be submi…

[com.nimbusds:nimbus-jose-jwt] Nimbus JOSE+JWT missing overflow check

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/09/2022

In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so that different …

[com.typesafe.play:play_2.12] Play Framework’s Assets controller vulnerable to directory traversal

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/23/2022

A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially …

[org.richfaces:richfaces] Remote code execution due to insecure deserialization

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/04/2022

A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of securit…

[org.vivoweb:vitro-project] Command Injection in VIVO Vitro

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request…

[org.apache.orc:orc] Apache ORC vulnerable to Uncontrolled Recursion

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug is most likely denial-of-service against software that uses the ORC file parser. With the C++ parser, t…

Posts navigation

Previous Posts 1 … 32 33 34 35 36 … 39 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close