Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[io.dataease:dataease-plugin-common] Dataease v1.11.1 SQL Injection via parameter dataSourceId

  • Posted inseverity
  • Posted byGitHub
  • 07/23/202208/06/2022

Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId. Version 1.11.2 contains a fix.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-34115
https://github.com/dataease/dataease/issues/2428
https:/…

[io.dataease:dataease-plugin-common] Dataease before 1.11.2 allows arbitrary code execution via crafter plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 07/23/202207/28/2022

An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin. Version 1.11.2 contains a patch for the problem.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-34113
https://githu…

[io.dataease:dataease-plugin-common] Dataease before 1.11.2 access control issue allows attackers to arbitrarily uninstall plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 07/23/202207/28/2022

An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator. Version 1.11.2 contains a patch for this issue.
References

https://n…

[file-type] file-type vulnerable to Infinite Loop via malformed MKV file

  • Posted inUncategorized
  • Posted byGitHub
  • 07/22/202207/27/2022

An issue was discovered in the file-type package from 13.0.0 until 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive…

[islandora/islandora] Islandora 2.0 before 2.4.1 could allow any user to upload content into a repository

  • Posted inUncategorized
  • Posted byGitHub
  • 07/22/202207/22/2022

Impact
This vulnerability would allow any user, regardless of permissions, to upload content into a repository. This affects installations of Islandora core 2.0 or greater.
Patches
Upgrade immediately to the latest release of Islandora.
Workarounds
In …

[io.github.skylot:jadx-core] skylot jadx affected by Incorrect Behavior Order in vulnerable dependency

  • Posted inUncategorized
  • Posted byGitHub
  • 07/22/202207/22/2022

Impact
Vulnerable library protobuf-java 3.11.4 (CVE-2021-22569)
Patches
Dependency updated in jadx 1.4.3
References
According to the AquaSecurity report:

Also, Maven repository have links to this and other vulnerabilities from dependencies:
https://mv…

[cranelift-codegen] Cranelift vulnerable to miscompilation of constant values in division on AArch64

  • Posted inUncategorized
  • Posted byGitHub
  • 07/22/202207/26/2022

Impact
There was a bug in Wasmtime’s code generator, Cranelift, for AArch64 targets where constant divisors could result in incorrect division results at runtime. The translation rules for constants did not take into account whether sign- or zero-exten…

[@openzeppelin/contracts-upgradeable] OpenZeppelin Contracts’s SignatureChecker may revert on invalid EIP-1271 signers

  • Posted inseverity
  • Posted byGitHub
  • 07/22/202208/04/2022

Impact
SignatureChecker.isValidSignatureNow is not expected to revert. However, an incorrect assumption about Solidity 0.8’s abi.decode allows some cases to revert, given a target contract that doesn’t implement EIP-1271 as expected.
The contracts that…

[@openzeppelin/contracts] OpenZeppelin Contracts’s ERC165Checker may revert instead of returning false

  • Posted inUncategorized
  • Posted byGitHub
  • 07/22/202207/26/2022

Impact
ERC165Checker.supportsInterface is designed to always successfully return a boolean, and under no circumstance revert. However, an incorrect assumption about Solidity 0.8’s abi.decode allows some cases to revert, given a target contract that doe…

[tzinfo] TZInfo relative path traversal vulnerability allows loading of arbitrary files

  • Posted inHIGH
  • Posted byGitHub
  • 07/22/202208/11/2022

Impact
Affected versions

0.3.60 and earlier.
1.0.0 to 1.2.9 when used with the Ruby data source (tzinfo-data).

Vulnerability
With the Ruby data source (the tzinfo-data gem for tzinfo version 1.0.0 and later and built-in to earlier versions), time zon…

Posts navigation

Previous Posts 1 … 9 10 11 12 13 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close