Skip to content

トピトピニュース

Header Image
Category

LOW

70 Posts

Featured

Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[net.sf.mpxj-for-csharp] Temporary File Information Disclosure vulnerability in MPXJ
Posted byGitHub
[decode-uri-component] decode-uri-component vulnerable to Denial of Service (DoS)
Posted byGitHub
[sweetalert2] sweetalert2 v8.19.1 and above contains hidden functionality

[mdx-mermaid] Improper Control of Generation of Code (‘Code Injection’) in mdx-mermaid

  • Posted inLOW
  • Posted byGitHub
  • 09/01/202209/08/2022

Impact
Arbitary javascript injection
Modify any mermaid code blocks with the following code and the code inside will execute when the component is loaded by MDXjs
` + (function () {
// Put Javascript code here
return ”
}()) + `

The block below sh…

[org.wildfly.core:wildfly-server] wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault

  • Posted inLOW
  • Posted byGitHub
  • 08/27/202209/03/2022

A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they sh…

[org.jenkins-ci.plugins:collabnet] RabbitMQ password stored in plain text by Jenkins CollabNet Plugins Plugin

  • Posted inLOW
  • Posted byGitHub
  • 08/24/202211/30/2022

Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
References

https://…

[katello] Katello cleartext password storage issue

  • Posted inLOW
  • Posted byGitHub
  • 05/25/202210/20/2022

A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.2. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credent…

[com.elasticbox.jenkins-ci.plugins:elasticbox] Cleartext Storage of Sensitive Information in Jenkins ElasticBox CI Plugin

  • Posted inLOW
  • Posted byGitHub
  • 05/25/202211/02/2022

Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
References

https://nvd.nist.gov/vuln/detail/CVE-2019…

[org.gradle:gradle-core] Use of a weak cryptographic algorithm in Gradle

  • Posted inLOW
  • Posted byGitHub
  • 05/25/202211/02/2022

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
References

https://nvd.nist….

[org.apache.tomcat:tomcat] Inconsistent documentation in Apache Tomcat

  • Posted inLOW
  • Posted byGitHub
  • 05/14/202211/04/2022

As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script t…

[com.nimbusds:nimbus-jose-jwt] Nimbus JOSE+JWT vulnerable to padding oracle attack

  • Posted inLOW
  • Posted byGitHub
  • 05/13/202211/09/2022

Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-12973
https://bitbu…

[org.jboss.ws:jbossws-common] JBossWS vulnerable to uncontrolled recursion

  • Posted inLOW
  • Posted byGitHub
  • 05/13/202211/08/2022

DOMUtils.java in org.jboss.ws:jbossws-common does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOC…

[org.apache.activemq:activemq-openwire-generator] ActiveMQ’s OpenWire protocol exposes certain system details as plain text

  • Posted inLOW
  • Posted byGitHub
  • 05/13/202211/23/2022

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-15709
https://lists.apa…

Posts navigation

Previous Posts 1 … 4 5 6 7 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close