Skip to content

トピトピニュース

Header Image
Category

LOW

70 Posts

Featured

Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[net.sf.mpxj-for-csharp] Temporary File Information Disclosure vulnerability in MPXJ
Posted byGitHub
[decode-uri-component] decode-uri-component vulnerable to Denial of Service (DoS)
Posted byGitHub
[sweetalert2] sweetalert2 v8.19.1 and above contains hidden functionality

[backdrop/backdrop] Cross-site Scripting in Backdrop CMS

  • Posted inLOW
  • Posted byGitHub
  • 11/22/202211/22/2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content. The account must have admin privileges.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-42096
https://github.com/backdrop/ba…

[dalli] Unsanitized input leading to code injection in Dalli

  • Posted inLOW
  • Posted byGitHub
  • 11/20/202211/27/2022

A vulnerability was found in Dalli. Affected is the function self.meta_set of the file lib/dalli/protocol/meta/request_formatter.rb of the component Meta Protocol Handler. The manipulation leads to injection. The exploit has been disclosed to the publi…

[github.com/moby/moby] Container build can leak any path on the host into the container

  • Posted inLOW
  • Posted byGitHub
  • 11/11/202211/11/2022

Description
Moby is the open source Linux container runtime and set of components used to build a variety of downstream container runtimes, including Docker CE, Mirantis Container Runtime (formerly Docker EE), and Docker Desktop. Moby allows for buildi…

[github.com/hashicorp/nomad] HashiCorp Nomad vulnerable to Insufficient Session Expiration

  • Posted inLOW
  • Posted byGitHub
  • 11/10/202211/11/2022

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3867
https://discuss.hashicor…

[Tauri] Tauri Filesystem Scope can be Partially Bypassed

  • Posted inLOW
  • Posted byGitHub
  • 11/09/202211/12/2022

Impact
Due to incorrect escaping of special characters in paths selected via the file dialog and drag and drop functionality, it was possible to partially bypass the fs scope definition. It was not possible to traverse into arbitrary paths, as the issu…

[fluentd] fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)

  • Posted inLOW
  • Posted byGitHub
  • 11/03/202211/08/2022

Impact
A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads.
Fluentd setups are only affected if the environment variable FL…

[actionpack] Cross-site Scripting in actionpack

  • Posted inLOW
  • Posted byGitHub
  • 10/27/202210/29/2022

actionpack from the Ruby on Rails project is vulnerable to Cross-site Scripting in the Route Error Page. This issue has been patched with this commit. There are no known workarounds for this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-…

[ses] Hardening of TypedArrays with non-canonical numeric property names in SES

  • Posted inLOW
  • Posted byGitHub
  • 10/21/202210/21/2022

Impact
What kind of vulnerability is it? Who is impacted?
In Hardened JavaScript, programs can harden objects to safely share objects with co-tenant programs without risk of these other programs tampering with their API surface. Hardening does not guar…

[csrf-csrf] Incorrect default cookie name and recommendation

  • Posted inLOW
  • Posted byGitHub
  • 10/11/202210/11/2022

Impact
What kind of vulnerability is it? Who is impacted?
The default cookie name (and documentation recommendation) was prefixed with Host__ instead of __Host-. The point of this prefix is for additional security, to ensure that, when no domain option…

[go.etcd.io/etcd/client/v3] etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery

  • Posted inLOW
  • Posted byGitHub
  • 10/07/202210/07/2022

Vulnerability type
Data Validation
Detail
When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.
References
Find out more on this vulnerability in t…

Posts navigation

Previous Posts 1 2 3 4 … 7 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close