Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[org.webjars.npm:vuetify] Vuetify Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 09/19/202209/22/2022

The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the ‘eventName’ function within the VCalendar component.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-25…

[snipe/snipe-it] Snipe-IT vulnerable to Improper Authentication

  • Posted inMODERATE
  • Posted byGitHub
  • 09/18/202209/23/2022

Snipe-IT prior to 6.0.10 is vulnerable to Improper Authentication. A user without the View and Modify License Files permission may access files uploaded to licenses as long as they have the View permission for licenses.
References

https://nvd.nist.gov…

[librenms/librenms] LibreNMS stored Cross-site Scripting via Schedule Maintenance `Title` parameter

  • Posted inMODERATE
  • Posted byGitHub
  • 09/18/202209/21/2022

LibreNMS versions 22.8.0 and prior allow attackers to execute arbitrary JavaScript code via the Schedule Maintenance Title parameter. A patch is available and anticipated to be part of version 22.9.0.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[rdiffweb] rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users

  • Posted inMODERATE
  • Posted byGitHub
  • 09/18/202209/23/2022

rdiffweb prior to 2.4.5 is vulnerable to Cross-Site Request Forgery (CSRF). An attacker exploiting this vulnerability can use it to delete repositories and users.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3232
https://github.com/ikus060/rdi…

[org.codehaus.jettison:jettison] Jettison parser crash by stackoverflow

  • Posted inMODERATE
  • Posted byGitHub
  • 09/17/202210/19/2022

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect…

[craftcms/cms] Craft CMS Cross site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 09/17/202209/22/2022

Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37248
https://github.com/craftcms/cms/commit/cedeba0609e4b173cd584dae7f33c5f713f19627
https://labs.integrity.pt/…

[craftcms/cms] Craft CMS Stored Cross-site Scripting in User Addresses Title

  • Posted inMODERATE
  • Posted byGitHub
  • 09/17/202209/22/2022

Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37250
https://github.com/craftcms/cms/commit/cdc9cb66d0716c9552e4113c8e426fd1a31f9516
https://labs.integrity.pt/…

[craftcms/cms] Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts

  • Posted inMODERATE
  • Posted byGitHub
  • 09/17/202209/27/2022

Craft CMS 3.70-RC1–3.7.55.1 and 4.0.0-RC1–4.2.0.1 are vulnerable to Cross Site Scripting (XSS) via entry revisions and drafts. Versions 3.7.55.2 and 4.2.1 contain patches for this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37251
https…

[craftcms/cms] Craft CMS vulnerable to stored Cross-site Scripting via /admin/settings/fields page

  • Posted inMODERATE
  • Posted byGitHub
  • 09/17/202209/23/2022

Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37247
https://github.com/craftcms/cms/commit/cedeba0609e4b173cd584dae7f33c5f713f19627
https://…

[tensorflow-gpu] TensorFlow vulnerable to `CHECK` fail in `LRNGrad`

  • Posted inMODERATE
  • Posted byGitHub
  • 09/17/202209/20/2022

Impact
If LRNGrad is given an output_image input tensor that is not 4-D, it results in a CHECK fail that can be used to trigger a denial of service attack.
import tensorflow as tf
depth_radius = 1
bias = 1.59018219
alpha = 0.117728651
beta = 0.40442705…

Posts navigation

Previous Posts 1 … 24 25 26 27 28 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close