Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[org.jenkins-ci.plugins:katalon] Jenkins Katalon Plugin vulnerable to Cross-Site Request Forgery

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stor…

[org.jenkins-ci.plugins:katalon] Jenkins Katalon Plugin Missing Authorization vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through an…

[github.com/fluxcd/source-controller] Improper use of metav1.Duration allows for Denial of Service

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/26/2022

Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec….

[com.alibaba:hessian-lite] Hessian Lite for Apache Dubbo deserialization vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 10/19/202210/20/2022

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and …

[org.apache.isis.core:isis-core] Apache Isis Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 10/19/202210/20/2022

Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar an…

[org.apache.isis.core:isis-core] Apache Isis webconsole module may directly query the database in prototype mode

  • Posted inMODERATE
  • Posted byGitHub
  • 10/19/202210/20/2022

When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to directly query the database. It was felt that it is safer to require the developer to explicitly enable th…

[getkirby/cms] Kirby CMS vulnerable to user enumeration in the brute force protection

  • Posted inMODERATE
  • Posted byGitHub
  • 10/19/202210/28/2022

TL;DR
This vulnerability affects all Kirby sites with user accounts (unless Kirby’s API and Panel are disabled in the config). It can only be exploited for targeted attacks because the attack does not scale to brute force.

Introduction
User enumeratio…

[getkirby/cms] Kirby CMS vulnerable to user enumeration in the code-based login and password reset forms

  • Posted inMODERATE
  • Posted byGitHub
  • 10/19/202210/26/2022

TL;DR
This vulnerability only affects you if you are using the code or password-reset auth method with the auth.methods option. It can only be successfully exploited under server configuration conditions outside of the attacker’s control.

Introduction…

[oro/commerce] OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration

  • Posted inMODERATE
  • Posted byGitHub
  • 10/19/202210/19/2022

Impact
Shipping rule edit page is vulnerable to cross site scripting (XSS) payload added to UPS Surcharge field. The attacker should have permission to create or edit a shipping rule.
References

https://github.com/oroinc/orocommerce/security/advisorie…

[nokogiri] Update bundled libxml2 to v2.10.3 to resolve multiple CVEs

  • Posted inMODERATE
  • Posted byGitHub
  • 10/19/202210/19/2022

Summary
Nokogiri v1.13.9 upgrades the packaged version of its dependency libxml2 to v2.10.3 from v2.9.14.
libxml2 v2.10.3 addresses the following known vulnerabilities:

CVE-2022-2309
CVE-2022-40304
CVE-2022-40303

Please note that this advisory only a…

Posts navigation

Previous Posts 1 … 14 15 16 17 18 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close