Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[rdiffweb] rdiffweb 2.4.1 Missing Custom Error Page

  • Posted inMODERATE
  • Posted byGitHub
  • 09/14/202209/15/2022

rdiffweb version 2.4.1 is set to a default and leaks error information. Version 2.4.2 fixes this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3175
https://huntr.dev/bounties/c40badc3-c9e7-4b69-9e2e-2b9f05865159
https://github.com/ikus06…

[github.com/containers/podman/v4] Podman’s incorrect handling of the supplementary groups may lead to data disclosure, modification

  • Posted inMODERATE
  • Posted byGitHub
  • 09/14/202209/15/2022

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are …

[github.com/containers/buildah] Buildah’s incorrect handling of the supplementary groups before v1.27.1 may lead to data disclosure, modification

  • Posted inMODERATE
  • Posted byGitHub
  • 09/14/202209/15/2022

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are…

[org.wildfly.bom:wildfly] WildFly vulnerable to Insecure Default Initialization of Resource

  • Posted inMODERATE
  • Posted byGitHub
  • 09/14/202209/15/2022

A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-1278
https://bugzilla.redhat.com/show_bug.cgi?id=2073401
https:/…

[lief] LIEF contains segmentation violation

  • Posted inMODERATE
  • Posted byGitHub
  • 09/14/202209/21/2022

LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp. Commit 7acf0bc4224081d4f425fcc8b2e361b95291d878 contains a patch.
References

https://nvd.n…

[lief] LIEF vulnerable to heap based buffer overflow

  • Posted inMODERATE
  • Posted byGitHub
  • 09/14/202209/21/2022

LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc. Commit 53bf680ef494a835e2c4a5de328ca85416a03a5a contains a patch.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38306
https://github.c…

[lief] LIEF contains a segmentation violation

  • Posted inMODERATE
  • Posted byGitHub
  • 09/14/202209/21/2022

LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69. A patch is available at commit ca938740264f1fcb18f91cba8e4039c518ecb75b.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38497
https://githu…

[moodle/moodle] Moodle Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 09/14/202209/22/2022

In certain Moodle products after creating a course, it is possible to add in a arbitrary “Topic” a resource, in this case a “Database” with the type “Text” where its values “Field name” and “Field description” are vulnerable to Cross Site Scripting Sto…

[io.pebbletemplates:pebble] Pebble Templates protection mechanism bypass can lead to arbitrary code execution

  • Posted inMODERATE
  • Posted byGitHub
  • 09/13/202209/15/2022

Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37767
https://github.com/Y4tacker/Web-Security/issues/3
https://github…

[github.com/gophish/gophish] Gophish before 0.12.0 vulnerable to Open Redirect

  • Posted inMODERATE
  • Posted byGitHub
  • 09/12/202209/15/2022

This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue(“next”)) to extract path and eventually redirect user to a relative URL, b…

Posts navigation

Previous Posts 1 … 28 29 30 31 32 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close