Skip to content

トピトピニュース

Header Image
Category

HIGH

381 Posts

Featured

Posted byGitHub
[phpxmlrpc/phpxmlrpc] code injection in phpxmlrpc/phpxmlrpc
Posted byGitHub
[ghost] ghost vulnerable to unauthorized newsletter modification via improper access controls
Posted byGitHub
[microweber/microweber] Account Takeover Through Password Reset Poisoning
Posted byGitHub
[apache-airflow] OS Command Injection in Apache Airflow

[org.jvnet.hudson.plugins:hipchat] Jenkins HipChat Plugin allows credential capture due to incorrect authorization

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/23/2022

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified…

[org.apache.geode:geode-core] Apache Geode vulnerable to Incorrect Authorization

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be …

[org.apache.struts:struts2-core] Code injection in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/12/2022

A vulnerability introduced by forcing parameter inclusion in the URL and Anchor Tag allows remote command execution, session access and manipulation and XSS attacks.
both the s:url and s:a tag provide an includeParams attribute.
The main scope of that …

[org.apache.struts:struts2-core] Code injection in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/04/2022

The Struts 2 DefaultActionMapper supports a method for short-circuit navigation state changes by prefixing parameters with “action:” or “redirect:”, followed by a desired navigational target expression. This mechanism was intended to help with attachin…

[oauthenticator] JupyterHub OAuthenticator elevation of privilege

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202209/13/2022

An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in…

[Microsoft.NETCore.Jit] .NET Core Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202210/26/2022

.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka “.NET Core Denial of Service Vulnerability”.
References

https://nvd.nist.gov/vuln/detai…

[org.jenkins-ci.main:jenkins-core] Improper Authorization in Jenkins Core

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me …

[org.jenkins-ci.main:jenkins-core] Improper Authorization in Jenkins Core

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefin…

[org.apache.mesos:mesos] Docker image code execution with Apache Mesos

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1…

[io.jenkins.plugins:atlassian-bitbucket-server-integration] Stored XSS vulnerability in Jenkins Bitbucket Server Integration Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 03/30/202211/30/2022

Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consu…

Posts navigation

Previous Posts 1 … 33 34 35 36 37 … 39 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close