Skip to content

Underground News

Header Image
Archive

Month: May 2022

646 Posts

Featured

Posted byUDiscoverMusic.
デフ・レパード、新作発売に合わせて新たなマッチ3パズルゲーム「Let’s Rock It」を発表
Posted byUDiscoverMusic.
【発売15周年】リアーナ『Good Girl Gone Bad』解説:大胆な変身を見せ、時代を象徴する存在となった第一歩
Posted byマイナビニュース
デル、14型の小型でNVIDIA T550搭載のモバイルワークステーション「Precision 3470」
Posted byマイナビニュース
FRONTIER、第11世代Intel Core搭載の15.6型ノートPC「NLTシリーズ」

[org.jenkins-ci.plugins:script-security] Improper Input Validation in Jenkins Script Security Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
References

https://nvd.ni…

[codecov] Improper Neutralization of Special Elements in Output Used by a Downstream Component in Codecov

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/28/2022

Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the “gcov-args” argument.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-7596
https://snyk.io/vuln/SNYK-JS-CODECOV-543183
https://github.com/advisories/GHS…

[waitress] Inconsistent Interpretation of HTTP Requests in Waitress

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/28/2022

Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Cont…

[Microsoft.WindowsDesktop.App.Ref] Remote code execution in Microsoft.WindowsDesktop.App.Ref

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202207/29/2022

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka ‘.NET F…

[Microsoft.AspNetCore.Http.Connections] Remote code execution in ASP.NET Core

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202207/08/2022

A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka ‘ASP.NET…

[Microsoft.AspNetCore.App] Denial of service in ASP.NET Core

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202207/08/2022

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka ‘ASP.NET Core Denial of Service Vulnerability’.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-0602
https://access.redhat.com/errata/RHSA-2020:0130
h…

[pillow] Buffer Copy without Checking Size of Input in Pillow

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-5311
https://github.com/python-pillow/Pillow/commit/a79b65c47c7dc6fe623aadf09aa6192fc54548f3
https://access.redhat.com/er…

[swagger-ui] Improper Neutralization of Input During Web Page Generation in swagger-ui

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202207/07/2022

swagger-ui has XSS in key names
References

https://nvd.nist.gov/vuln/detail/CVE-2016-1000229
https://access.redhat.com/errata/RHSA-2017:0868
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000229
https://github.com/advisories/GHSA-h8wp-wgcq-qhrf

[org.jenkins-ci.plugins:script-security] Incorrect Authorization in Jenkins Script Security Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/28/2022

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.
References

https://nvd.nist.gov/vu…

[pyarrow] Missing Initialization of Resource in Apache Arrow

  • Posted inseverity
  • Posted byGitHub
  • 05/25/202208/06/2022

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby an…

Posts navigation

Previous Posts 1 … 26 27 28 29 30 … 65 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close