Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[org.jenkins-ci.plugins:bigpanda-jenkins] Jenkins BigPanda Notifier Plugin Missing Password Field Masking

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/23/2022

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-41248
https:…

[org.jenkins-ci.plugins:apprenda] Jenkins Apprenda Plugin has Missing Authorization vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/23/2022

A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-41251
https://www.jen…

[rdiffweb] rdiffweb has insecure HTTP cookies

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/27/2022

In rdiffweb prior to version 2.4.6, the cookie session_id does not have a secure attribute when the URL is invalid. Version 2.4.6 contains a fix for the issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3250
https://github.com/ikus060/rdiffw…

[awesome-support/awesome-support] Awesome Support vulnerable to persistent cross-site scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/30/2022

Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38073
https://patchstack.com/database/vul…

[rdiffweb] rdiffweb CSRF could lead to disabling notifications in user profile

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/23/2022

rdiffweb prior to 2.4.6 is vulnerable to Cross-Site Request Forgery (CSRF), which could lead to disabling notifications in a user’s profile.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3233
https://github.com/ikus060/rdiffweb/commit/18a5aabd4…

[@netlify/ipx] @netlify/ipx vulnerable to Full Response SSRF and Stored XSS via Cache Poisoning and Improper Host Validation

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/28/2022

Impact
By sending specially crafted headers an attacker can bypass the source image domain allowlist, causing the handler to load and return arbitrary images. Because the response is cached globally, this image will then be served to visitors without r…

[fhir-works-on-aws-authz-smart] fhir-works-on-aws-authz-smart handles permissions improperly

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/27/2022

Impact
This issue allows a client of the API to retrieve more information than the client’s OAuth scope permits when making “search-type” requests. This issue would not allow a client to retrieve information about individuals other than those the clien…

[parse-server] parse-server’s session object properties can be updated by foreign user if object ID is known

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/27/2022

Impact
A foreign user can write to the session object of another user if the session object ID is known. For example, a foreign user can assign the session object to their own user by writing to the user field and then read any custom fields of that se…

[commonmarker] Unbounded resource exhaustion in cmark-gfm autolink extension may lead to denial of service

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/22/2022

Impact
CommonMarker uses cmark-gfm for rendering Github Flavored Markdown. A polynomial time complexity issue in cmark-gfm’s autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.
Patches
This vulnerability has b…

[jwcrypto] jwcrypto token substitution can lead to authentication bypass

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/22/2022

The JWT code can auto-detect the type of token being provided, and this can lead the application to incorrect conclusions about the trustworthiness of the token.
Quoting the private disclosure we received : “Under certain circumstances, it is possible …

Posts navigation

Previous Posts 1 … 22 23 24 25 26 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close