Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[librenms/librenms] Cross-site Scripting in librenms/librenms

  • Posted inMODERATE
  • Posted byGitHub
  • 11/20/202211/22/2022

Cross-site Scripting (XSS) – Stored in GitHub repository librenms/librenms prior to 22.10.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3516
https://github.com/librenms/librenms/commit/8e85698aa3aa4884c2f3d6c987542477eb64f07c
https://huntr.d…

[librenms/librenms] Cross-site Scripting in librenms/librenms

  • Posted inMODERATE
  • Posted byGitHub
  • 11/20/202211/22/2022

Cross-site Scripting (XSS) – Generic in GitHub repository librenms/librenms prior to 22.10.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4069
https://github.com/librenms/librenms/commit/8383376f1355812e09ec0c2af67f6d46891b7ba7
https://huntr….

[github.com/oam-dev/kubevela] List helm chart endpoint of VelaUX APIserver has SSRF vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 11/19/202211/19/2022

Impact
Users using the VelaUX APIServer could be affected by this vulnerability.
When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.
Patches
For users …

[rdiffweb] Rdiffweb vulnerable to Missing Authentication for Critical Function

  • Posted inMODERATE
  • Posted byGitHub
  • 11/17/202211/29/2022

Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4018
https://github.com/ikus060/rdiffweb/commit/f2a32f2a9f3fb8be1a9432ac3d81d3aacdb13095
https://…

[org.apache.archiva:archiva-common] Apache Archiva subject to arbitrary directory deletion by users.

  • Posted inMODERATE
  • Posted byGitHub
  • 11/16/202211/22/2022

Apache Archiva prior to 2.2.9 allows an authenticated user to delete arbitrary directories. Users with write permissions to a repository can delete arbitrary directories.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-40309
https://lists.apache….

[concrete5/concrete5] Concrete CMS vulnerable to Reflected Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS – user can cause an administrator to trigger reflected XSS with a url if the targeted administrator is using an old browser that lacks XSS protect…

[concrete5/concrete5] Concrete CMS vulnerable to Reflected Cross-site Scripting via image manipulation library

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the image manipulation library due to un-sanitized output.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43694
https://documentation.co…

[concrete5/concrete5] Concrete CMS vulnerable to Reflected Cross-Site Scripting via dashboard icons

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboard icons due to un-sanitized output. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
References

https://nvd.nist.gov/vuln/…

[concrete5/concrete5] Concrete CMS vulnerable to Cross-site Scripting via multilingual report

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multilingual report due to un-sanitized output. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
References

https://nvd.nist.gov/v…

[concrete5/concrete5] Concrete CMS vulnerable to Uncontrolled Resource Consumption leading to DoS

  • Posted inMODERATE
  • Posted byGitHub
  • 11/15/202211/22/2022

In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43686
https://documentati…

Posts navigation

Previous Posts 1 … 3 4 5 6 7 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close