「はやぶさ2」がリュウグウに着陸したことを示すデータを確認し、抱き合って喜ぶ津田雄一プロジェクトマネージャら=2019年2月、JAXA提供 [PR] 探査機「はやぶさ2」の総責任者として、6年50億キロの旅を成功させた宇宙航空研究開発機構(JAXA)の津田雄一・プロジェクトマネージャ。小惑星に2度着陸し、……
『トップガン新作』巡りパラマウントが著作権侵害で訴えられる コロナ禍の公開延期が焦点か
パラマウント・ピクチャーズが映画『トップガン マーヴェリック』を巡り著作権侵害で訴えられている。イス…
二宮和也主演・冒険エンタメ映画『TANG タング』タングと未来のaibo場面写真&オフショット解禁
8月11日(木・祝)に公開の二宮和也2年ぶりとなる主演映画『TANG タング』より、場面写真とオフシ…
[semantic-release] Exposure of Sensitive Information to an Unauthorized Actor in semantic-release
Impact
What kind of vulnerability is it? Who is impacted?
Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by encodeURI. Occurrence is further limited…
Look: Lindsey Vonn’s Best ‘Body Paint’ Swimsuit Photos
By Andrew Holleran Over the years, several notable athletes and sports figures have posed for the iconic Sports Illustrated Swimsuit issue. Former United States Olympic skier Lindsey Vonn is among those who have been featured in the issue. Vonn, one of…
[cookiecutter] OS Command Injection in cookiecutter
The package cookiecutter before 2.1.1 is vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional fl…
[mechanize] Authorization header leak on port redirect in mechanize
Summary
Mechanize (rubygem) < v2.8.5 leaks the Authorization header after a redirect to a different port on the same site.
Mitigation
Upgrade to Mechanize v2.8.5 or later.
Notes
See https://curl.se/docs/CVE-2022-27776.html for a similar vulnerabilit…
[guzzlehttp/guzzle] Failure to strip the Cookie header on change in host or HTTP downgrade
Impact
Cookie headers on requests are sensitive information. On making a request using the https scheme to a server which responds with a redirect to a URI with the http scheme, or on making a request to a server which responds with a redirect to a a U…
[guzzlehttp/guzzle] Fix failure to strip Authorization header on HTTP downgrade
Impact
Authorization headers on requests are sensitive information. On making a request using the https scheme to a server which responds with a redirect to a URI with the http scheme, we should not forward the Authorization header on. This is much the…
ネトフリ人気ドラマの28歳主演女優 マドンナの伝記映画の主役抜てきへ 大役を巡る“競争”勝ち抜く
女優ジュリア・ガーナー(28)が、マドンナの新作伝記映画で主役に抜擢されそうだ。ネットフリックスの人…