Skip to content

Underground News

Header Image
Archive

Month: May 2022

646 Posts

Featured

Posted byUDiscoverMusic.
デフ・レパード、新作発売に合わせて新たなマッチ3パズルゲーム「Let’s Rock It」を発表
Posted byUDiscoverMusic.
【発売15周年】リアーナ『Good Girl Gone Bad』解説:大胆な変身を見せ、時代を象徴する存在となった第一歩
Posted byマイナビニュース
デル、14型の小型でNVIDIA T550搭載のモバイルワークステーション「Precision 3470」
Posted byマイナビニュース
FRONTIER、第11世代Intel Core搭載の15.6型ノートPC「NLTシリーズ」

[edu.stanford.nlp:stanford-corenlp] Improper Restriction of XML External Entity Reference in Stanford CoreNLP

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/22/2022

corenlp is vulnerable to Improper Restriction of XML External Entity Reference
References

https://nvd.nist.gov/vuln/detail/CVE-2021-3869
https://github.com/stanfordnlp/corenlp/commit/5d83f1e8482ca304db8be726cad89554c88f136a
https://huntr.dev/bounties/…

[apache-superset] Improper Neutralization of Input During Web Page Generation in Apache Superset

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/22/2022

Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.
References

https://nv…

[apache-superset] Improper Neutralization of Special Elements used in an SQL Command in Apache Superset

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/22/2022

Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.
References

https://nvd.nist.gov/vuln/…

[edu.stanford.nlp:stanford-corenlp] Improper Restriction of XML External Entity Reference in Stanford CoreNLP

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/22/2022

corenlp is vulnerable to Improper Restriction of XML External Entity Reference
References

https://nvd.nist.gov/vuln/detail/CVE-2021-3878
https://github.com/stanfordnlp/corenlp/commit/e5bbe135a02a74b952396751ed3015e8b8252e99
https://huntr.dev/bounties/…

[apache-airflow] Missing Authentication for Critical Function in Apache Airflow

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202207/26/2022

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, infor…

[salt] Improper Authentication in SaltStack Salt

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/23/2022

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper be…

[openssl-src] Read buffer overruns processing ASN.1 strings

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/17/2022

ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the str…

[org.owasp:csrfguard] Cross-Site Request Forgery in OWASP CSRFGuard

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/22/2022

In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-28490
https://github.com/reidmefirst/vuln-disclosure/blob/main/2021-01.txt
ht…

[mongors] Exposure of Sensitive Information to an Unauthorized Actor in MongoDB Rust Driver

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/18/2022

Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user’s logging infrastructure could then potentially ingest thes…

[org.neo4j:neo4j-kernel] Improper Privilege Management in Neo4j Graph Database

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/22/2022

A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 could allow authenticated users to execute commands with elevated privileges.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-34802
https://neo4j….

Posts navigation

Previous Posts 1 … 20 21 22 23 24 … 65 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close