Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[apache-airflow] Apache Airflow Open Redirect vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/09/2022

In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver’s /confirm endpoint.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43985
https://github.com/apache/airflow/pull/27143
https://lists.apache.org/thread/m13y9s5…

[org.apache.sling:org.apache.sling.cms] Apache Sling App CMS vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/04/2022

A Cross-site Scripting vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.
References

https://nvd.nist.gov/vuln/…

[apollo-server-core] Batched HTTP requests may set incorrect `cache-control` response header

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/03/2022

Impact
In Apollo Server 3 and 4, the cache-control HTTP response header may not reflect the cache policy that should apply to an HTTP request when that HTTP request contains multiple operations using HTTP batching. This could lead to data being inappro…

[ckb] ckb: Large dep group requires a lot of resources to process but the cost to commit the transaction is very low.

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/03/2022

Impact
When a transaction contains a dep group with many cells, the resources required to process it are not linear to the transaction size nor spent script cycles.
Patches
In 0.43.3, nodes drop the transactions relayed to them when they contain a dep…

[cryptography] Vulnerable OpenSSL included in cryptography wheels

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/2022

pyca/cryptography’s wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-38.0.3 are vulnerable to a number of security issues. More details about the vulnerabilities themselves can be found in http…

[tobiasbg/tablepress] TablePress Plugin vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 11/02/202211/03/2022

A cross-site scripting vulnerability was found in an unknown function of the component Table Import Handler. The manipulation of the argument Import data leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been …

[pyspark] Apache Spark vulnerable to Injection

  • Posted inMODERATE
  • Posted byGitHub
  • 11/02/202211/11/2022

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned…

[org.apache.dolphinscheduler:dolphinscheduler] Apache DolphinScheduler vulnerable to Path Traversal

  • Posted inMODERATE
  • Posted byGitHub
  • 11/02/202211/02/2022

When users add resources to the resource center with a relation path, this vulnerability will cause path traversal issues for logged-in users. Users should upgrade to version 3.0.0 to avoid this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2…

[node-red-dashboard] node-red-dashboard vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 11/01/202211/04/2022

node-red-dashboard contains a cross-site scripting vulnerability. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The attack may be initiated remotely. The iss…

[org.apache.tomcat:tomcat] Apache Tomcat may reject request containing invalid Content-Length header

  • Posted inMODERATE
  • Posted byGitHub
  • 11/01/202211/02/2022

If Apache Tomcat 8.5.0 to 8.5.52, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request conta…

Posts navigation

Previous Posts 1 … 8 9 10 11 12 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close