Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[nodebb] NodeBB vulnerable to Cross-Site Request Forgery

  • Posted inMODERATE
  • Posted byGitHub
  • 11/14/202211/19/2022

A vulnerability was found in NodeBB up to 2.5.7. This affects an unknown part of the file /register/abort. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 2.5.8 is able to addre…

[nukeviet/nukeviet] NukeView CMS vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 11/13/202211/16/2022

NukeView CMS has been found to be vulnerable to Cross-site Scripting. Affected by this issue is the function filterAttr of the file vendor/vinades/nukeviet/Core/Request.php of the component Data URL Handler. The manipulation of the argument attrSubSet …

[matrix-appservice-irc] Matrix-appservice-irc vulnerable to sql injection via roomIds argument

  • Posted inMODERATE
  • Posted byGitHub
  • 11/13/202211/18/2022

A vulnerability was found in matrix-appservice-irc up to 0.35.1. This vulnerability affects the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection. Upgrading to version 0.36.0 is able to address …

[org.deeplearning4j:dl4j-examples] Use of unclaimed s3 bucket in tests and examples

  • Posted inMODERATE
  • Posted byGitHub
  • 11/11/202211/17/2022

Impact
People who use some older NLP examples that reference the old S3 bucket.
Patches
The problem has been patched. Upgrade to snapshots for now. A release will be published later to address this due to the vulnerability mostly being examples and 1 …

[wasmtime] Wasmtime out of bounds read/write with zero-memory-pages configuration

  • Posted inMODERATE
  • Posted byGitHub
  • 11/11/202211/15/2022

Impact
There is a bug in Wasmtime’s implementation of its pooling instance allocator when the allocator is configured to give WebAssembly instances a maximum of zero pages of memory. In this configuration the virtual memory mapping for WebAssembly memo…

[github.com/phachon/mm-wiki] mm-wiki is vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/11/202211/16/2022

mm-wki v0.2.1 is vulnerable to Cross Site Scripting (XSS).
References

https://nvd.nist.gov/vuln/detail/CVE-2021-40289
https://github.com/phachon/mm-wiki/issues/319
https://github.com/advisories/GHSA-99g5-5643-xphp

[readthedocs] Read the Docs vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/11/202211/11/2022

Impact
This vulnerability allowed a malicious user to serve arbitrary HTML files from the main application domain (readthedocs[.]org/readthedocs[.]com) by exploiting a vulnerability in the code that serves downloadable content from a project.
Exploiti…

[electron] Exfiltration of hashed SMB credentials on Windows via file:// redirect

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/10/2022

Impact
When following a redirect, Electron delays a check for redirecting to file:// URLs from other schemes. The contents of the file is not available to the renderer following the redirect, but if the redirect target is a SMB URL such as file://some….

[cleo] cleo is vulnerable to Regular Expression Denial of Service (ReDoS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/29/2022

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-42966
https://…

[pymatgen] pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/11/2022

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method.
References

https://nvd.nist.gov/vuln/detail/CVE-2022…

Posts navigation

Previous Posts 1 … 5 6 7 8 9 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close