Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[org.springframework.data:spring-data-jpa] Improper Neutralization of Wildcards or Matching Symbols

  • Posted inMODERATE
  • Posted byGitHub
  • 06/05/201910/06/2022

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results…

[slug] Regular Expression Denial of Service in slug

  • Posted inMODERATE
  • Posted byGitHub
  • 07/25/201809/20/2022

Affected versions of slug are vulnerable to a regular expression denial of service when parsing untrusted user input.
The issue is low severity, as it takes 50,000 characters to cause the event loop to block for 2 seconds,
About 50k characters can bloc…

[jquery-ui] Moderate severity vulnerability that affects jquery-ui

  • Posted inMODERATE
  • Posted byGitHub
  • 10/25/201709/08/2022

Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properl…

[puppet] Puppet allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service

  • Posted inMODERATE
  • Posted byGitHub
  • 10/25/201710/05/2022

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. …

[actionpack] Moderate severity vulnerability that affects actionpack

  • Posted inMODERATE
  • Posted byGitHub
  • 10/25/201707/16/2022

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prom…

Posts navigation

Previous Posts 1 … 49 50 51
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close