Skip to content

Underground News

Header Image
Archive

Month: May 2022

646 Posts

Featured

Posted byUDiscoverMusic.
デフ・レパード、新作発売に合わせて新たなマッチ3パズルゲーム「Let’s Rock It」を発表
Posted byUDiscoverMusic.
【発売15周年】リアーナ『Good Girl Gone Bad』解説:大胆な変身を見せ、時代を象徴する存在となった第一歩
Posted byマイナビニュース
デル、14型の小型でNVIDIA T550搭載のモバイルワークステーション「Precision 3470」
Posted byマイナビニュース
FRONTIER、第11世代Intel Core搭載の15.6型ノートPC「NLTシリーズ」

[org.apache.tomcat:tomcat] Directory Traversal in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/10/2022

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to byp…

[select2] Improper Neutralization of Input During Web Page Generation in Select2

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/07/2022

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[org.apache.activemq:activemq-client] Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/07/2022

Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References

https://nvd.nist.gov/vul…

[jupyter-notebook] Improper Neutralization of Input During Web Page Generation in Jupyter Notebook

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/24/2022

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated w…

[org.apache.tomcat:tomcat] Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/08/2022

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain “Tomcat internals” information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML doc…

[org.apache.tomcat:tomcat] Improper Access Control in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/07/2022

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers …

[org.apache.tomcat:tomcat] Insufficient Verification of Data Authenticity in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/01/2022

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poiso…

[suds] Improper Link Resolution Before File Access in Suds

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/09/2022

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
References

https://nvd.nist.gov/vuln/…

[org.wildfly.core:wildfly-server] Improper Limitation of a Pathname to a Restricted Directory in WildFly

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/30/2022

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the ‘Zip Slip’ vulnerability.
References

https:/…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/29/2022

A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of…

Posts navigation

Previous Posts 1 … 47 48 49 50 51 … 65 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close