Skip to content

Underground News

Header Image
Archive

Month: May 2022

646 Posts

Featured

Posted byUDiscoverMusic.
デフ・レパード、新作発売に合わせて新たなマッチ3パズルゲーム「Let’s Rock It」を発表
Posted byUDiscoverMusic.
【発売15周年】リアーナ『Good Girl Gone Bad』解説:大胆な変身を見せ、時代を象徴する存在となった第一歩
Posted byマイナビニュース
デル、14型の小型でNVIDIA T550搭載のモバイルワークステーション「Precision 3470」
Posted byマイナビニュース
FRONTIER、第11世代Intel Core搭載の15.6型ノートPC「NLTシリーズ」

[org.jetbrains.kotlin:kotlin-stdlib] Incorrect Default Permissions in JetBrains Kotlin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
References

https://nvd.nist.gov/vuln/detail/C…

[smallvec] Buffer overflow in SmallVec::insert_many

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/17/2022

An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-25900
https://rustsec.org/advisories/RUSTSE…

[jupyterhub] Cross-Site Request Forgery in JupyterHub

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36191
https://github.com/jupyte…

[@strikeentco/set] Prototype pollution in @strikeentco/set

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/18/2022

Prototype pollution vulnerability in ‘@strikeentco/set’ version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-28267
https://github.com/strikeentco/set/com…

[CKEditor4] Improper Neutralization of Input During Web Page Generation in CKEditor4

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
References

https://nvd…

[org.csanchez.jenkins.plugins:kubernetes] Missing Authorization in Jenkins Kubernetes Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2308
https://www.jenkins.io/security/advis…

[org.csanchez.jenkins.plugins:kubernetes] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2307
https://www.jenkins.io/security/advisory/2020-11-0…

[org.jenkins-ci.plugins:mercurial] Improper Restriction of XML External Entity Reference in Jenkins Mercurial Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2305
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2115
http…

[org.jenkins-ci.plugins:mercurial] Missing Authorization in Jenkins Mercurial Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2306
https://ww…

[org.wildfly:wildfly-dist] Uncontrolled Resource Consumption in WildFly

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an…

Posts navigation

Previous Posts 1 … 22 23 24 25 26 … 65 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close