Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[com.github.kevinsawicki:http-request] Missing certificate validation

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/04/2022

OSS Http Request (kevinsawicki/http-request) is missing SSL/TLS certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.
References

https://nv…

[Microsoft.NETCore.App.Runtime.ios-arm] Denial of service in .NET core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/02/2022

.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-1721
https://portal.msrc.micro…

[jupyterhub] Cross-Site Request Forgery in JupyterHub

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202209/10/2022

JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36191
https://github.com/jupyte…

[org.keycloak:keycloak-core] Keycloak vulnerable to Server-Side Request Forgery

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202210/08/2022

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) …

[Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64] Integer overflow in the bundled Brotli C library

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/01/2022

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a “one-shot” decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 Gi…

[expo] Expo on iOS is insecure due incorrect security attribute application

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202209/16/2022

secure-store in Expo through 9.1.0 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-24653
https://github.com/expo/expo/pull/926…

[org.jenkins-ci.main:jenkins-core] Improper Neutralization of Input During Web Page Generation in Jenkins

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/01/2022

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via ‘Trigger builds remotely’, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure per…

[org.jenkins-ci.main:jenkins-core] Improper Neutralization of Input During Web Page Generation in Jenkins

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202210/07/2022

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
References

https://nvd.nist…

[org.jenkins-ci.main:jenkins-core] Improper Neutralization of Input During Web Page Generation in Jenkins

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202210/07/2022

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2229
https://jenkins.io/security…

[org.apache.dubbo:dubbo-rpc-http-invoker] Deserialization of Untrusted Data in Apache Dubbo

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/05/2022

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This i…

Posts navigation

Previous Posts 1 … 35 36 37 38 39 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close