Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[yetiforce/yetiforce-crm] Cross site scripting in yetiforce/yetiforce-crm

  • Posted inMODERATE
  • Posted byGitHub
  • 08/23/202208/31/2022

Cross-site Scripting (XSS) – Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2890
https://github.com/yetiforcecompany/yetiforcecrm/commit/2c14baaf8dbc7fd82d5c585f2fa0c23528…

[eth-account] Regular expression denial of service in eth-account

  • Posted inMODERATE
  • Posted byGitHub
  • 08/23/202208/31/2022

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method
References

https://nvd.nist.gov/vuln/detail/CVE-2022-…

[yetiforce/yetiforce-crm] Cross site scripting in yetiforce/yetiforce-crm

  • Posted inMODERATE
  • Posted byGitHub
  • 08/22/202208/31/2022

Cross-site Scripting (XSS) – Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2885
https://github.com/yetiforcecompany/yetiforcecrm/commit/a9ad9ee089b575855b9e5e202b4990a158…

[getkirby/starterkit] Cross site scripting in getkirby/starterkit

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202208/31/2022

A stored cross-site scripting (XSS) vulnerability in Kirby’s Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-35174
h…

[frontier] Incorrect parsing of EVM reversion exit reason in RPC

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202208/27/2022

Impact
A low severity security issue was discovered affecting parsing of the RPC result of the exit reason in case of EVM reversion. In release build, this would cause the exit reason being incorrectly parsed and returned by RPC. In debug build, this w…

[kubevirt.io/kubevirt] Duplicate Advisory: KubeVirt arbitrary host file read from the VM

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202209/30/2022

Duplicate Advisory
This advisory is a duplicate of GHSA-qv98-3369-g364. This link is maintained to preserve external references.
Original Description
Summary
As part of a Kubevirt audit performed by NCC group, a finding dealing with systemic lack of pa…

[oqs] oqs’s Post-Quantum Key Encapsulation Mechanism SIKE broken

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202208/19/2022

Wouter Castryck and Thomas Decru presented an efficient key recovery attack on the SIDH protocol.
As a result, the secret key of SIKEp751 can be recovered in a matter of hours.
The SIKE and SIDH schemes will be removed from oqs 0.7.2.
An efficient key …

[notrinos/notrinos-erp] NotrinosERP Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 08/18/202208/31/2022

NotrinosERP version 0.7 and prior is vulnerable to stored cross-site scripting. A fix is available on the master branch of the repository.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2871
https://github.com/notrinos/notrinoserp/commit/0362778…

[rocksdb] rocksdb vulnerable to out-of-bounds read

  • Posted inMODERATE
  • Posted byGitHub
  • 08/13/202208/13/2022

Affected versions of this crate called the RocksDB C API
rocksdb_open_column_families_with_ttl() with a pointer to a single integer
TTL value, but one TTL value for each column family is expected.
This is only relevant when using
rocksdb::DBWithThreadM…

[update_by_case] update_by_case before 0.1.3 can be vulnerable to sql injection

  • Posted inMODERATE
  • Posted byGitHub
  • 08/12/202208/23/2022

Before version 0.1.3 update_by_case gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >= 0.1.3 that uses Arel instead to construct the resulting sql statement, with sanitized sql.
Refere…

Posts navigation

Previous Posts 1 … 33 34 35 36 37 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close