Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[snowflake-connector-python] snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/11/2022

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the get_file_transfer_type method.
References

https://nvd.nist.gov/vuln/…

[Lin-CMS] Lin CMS vulnerable to Improper Authentication

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/22/2022

An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-44244
https://gist.github.com/cai-niao98/58c97899695488bd73a73d56adf44c4c
https://github.co…

[github.com/hashicorp/nomad] HashiCorp Nomad vulnerable to non-sensitive metadata exposure

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/11/2022

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
References

https://nvd.nist.gov/vuln/detail/CVE-2022…

[intelliants/subrion] Subrion CMS is vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/10/2022

A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS version 4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.
Ref…

[feehi/cms] FeehiCMS is vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/11/2022

FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-43320
https://github.com/liufee/feehic…

[intelliants/subrion] Subrion CMS is vulnerable to Cross-Site Scripting (XSS)

  • Posted inMODERATE
  • Posted byGitHub
  • 11/10/202211/10/2022

A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS in version 4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
References

https://n…

[System.Data.SqlClient] .NET Information Disclosure Vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 11/09/202211/10/2022

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET, .NET Core and .NET Framework’s System.Data.SqlClient and Microsoft.Data.SqlClient NuGet Packages.
A vulnerability exists in System.Data.SqlClient and Mi…

[github.com/openfga/openfga] OpenFGA Authorization Bypass

  • Posted inMODERATE
  • Posted byGitHub
  • 11/09/202211/10/2022

Overview
During our internal security assessment, it was discovered that OpenFGA versions v0.2.4 and prior are vulnerable to authorization bypass under certain conditions.
Am I Affected?
You are affected by this vulnerability if you are using openfga/o…

[lzf] Invalid use of `mem::uninitialized` causes `use-of-uninitialized-value`

  • Posted inMODERATE
  • Posted byGitHub
  • 11/09/202211/09/2022

The compression and decompression function used mem:uninitialized to create an array of uninitialized values, to later write values into it. This later leads to reads from uninitialized memory.
The flaw was corrected in commit b633bf265e41c60dfce3be7ea…

[froxlor/froxlor] Froxlor vulnerable to code injection

  • Posted inMODERATE
  • Posted byGitHub
  • 11/06/202211/09/2022

Code Injection in GitHub repository froxlor/froxlor prior to version 0.10.38.2. There are currently no known workarounds, please upgrade to version 0.10.38.2.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3869
https://github.com/froxlor/froxlor…

Posts navigation

Previous Posts 1 … 6 7 8 9 10 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close