Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[skywalking-backend-js] Apache SkyWalking NodeJS Agent can lose availability if header includes illegal SkyWalking header

  • Posted inseverity
  • Posted byGitHub
  • 07/19/202208/06/2022

A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can’t establish the connection.
References

https://…

[dompdf/dompdf] Dompdf before v2.0.0 vulnerable to chroot check bypass

  • Posted inUncategorized
  • Posted byGitHub
  • 07/19/202207/26/2022

Dompdf prior to version 2.0.0 is vulnerable to a chroot check bypass, which could cause disclosure of png and jpeg files.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2400
https://github.com/dompdf/dompdf/commit/99aeec1efec9213e87098d42eb09439…

[org.webjars.npm:thenify] thenify before 3.3.1 made use of unsafe calls to `eval`.

  • Posted inUncategorized
  • Posted byGitHub
  • 07/19/202207/27/2022

Versions of thenify prior to 3.3.1 made use of unsafe calls to eval. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to eval.
References

https://github.com/thenables/thenify/issues…

[jquery-ui] jQuery UI Cross-site Scripting when refreshing a checkboxradio with an HTML-like initial text label

  • Posted inUncategorized
  • Posted byGitHub
  • 07/19/202207/20/2022

Impact
Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. If you call .checkboxradio( “refresh” ) on such a widget and the initial HTML contained encoded HTML entities…

[glob-parent] glob-parent before 6.0.1 and 5.1.2 vulnerable to Regular Expression Denial of Service (ReDoS)

  • Posted inUncategorized
  • Posted byGitHub
  • 07/19/202207/20/2022

glob-parent before 6.0.1 and 5.1.2 is vulnerable to Regular Expression Denial of Service (ReDoS). This issue is fixed in version 6.0.1 and 5.1.2.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-35065
https://github.com/opensearch-project/OpenSear…

[grunt-util-property] grunt-util-property 0.0.2 function call can add/modify properties of Object.prototype using a __proto__ payload

  • Posted inUncategorized
  • Posted byGitHub
  • 07/18/202207/22/2022

This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-7641
https://github.co…

[woocommerce/woocommerce] WooCommerce WordPress plugin before 6.6.0 vulnerable to stored HTML injection

  • Posted inUncategorized
  • Posted byGitHub
  • 07/18/202207/22/2022

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2099
https://wpscan.com/vulnerability/0316e5…

[org.apache.hive:hive] Apache Hive before 3.1.3 `CREATE` and `DROP` function operations do not check for necessary authorization.

  • Posted inUncategorized
  • Posted byGitHub
  • 07/17/202207/23/2022

Apache Hive before 3.1.3 CREATE and DROP function operations do not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This …

[OctoBot] Octobot before 0.4.4 mishandles Tentacles upload

  • Posted inUncategorized
  • Posted byGitHub
  • 07/17/202207/23/2022

WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-36711
https://github.com/Drakkar-Software/OctoBot/issues/1966
https://github.com/Drakkar-Sof…

[gollum] Gollum Cross-site Scripting vulnerability via filename parameter to New Page dialog

  • Posted inMODERATE
  • Posted byGitHub
  • 07/16/202208/11/2022

Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the ‘New Page’ dialog.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-35305
https://github.com/Szarny/
https://github.com/gollum/
https://github.com/gollum/gollum/re…

Posts navigation

Previous Posts 1 … 11 12 13 14 15 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close