Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[ganga] ganga before 8.5.10 allows absolute path traversal because the Flask send_file function is used unsafely

  • Posted inUncategorized
  • Posted byGitHub
  • 07/14/202207/26/2022

The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-31507
https://github.com/github/securitylab/issues/669#i…

[svelte] Svelte cross-site scripting prior to 3.49.0 due to when using objects during server-side rendering

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/16/2022

The package svelte before 3.49.0 is vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via ob…

[github.com/argoproj/argo-cd] Argo CD improper access control bug can allow malicious user to escalate privileges to admin level

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/22/2022

Impact
Impacts for versions starting with v1.0.0
All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
To perform the …

[sigs.k8s.io/aws-iam-authenticator] Improper Input Validation in aws-iam-authenticator

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/16/2022

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2385
https://github.com/kubernetes-sigs/aws-…

[Azure.Storage.Queues] Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/22/2022

Summary
The Azure Storage Encryption library in Java and other languages is vulnerable to a CBC Padding Oracle attack, similar to CVE-2020-8911. The library is not vulnerable to the equivalent of CVE-2020-8912, but only because it currently only suppor…

[io.github.karlatemp:unsafe-accessor] No security checking for UnsafeAccess.getInstance() in UnsafeAccessor

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/13/2022

Overview
Affected versions have no limit to using unsafe-accessor. Can be ignored if SecurityCheck.AccessLimiter not setup
Details
If UA was loaded as a named module, the internal data of UA will be protected by JVM and others can only access UA via UA…

[cuyz/valinor] Valinor error messages leading to potential data exfiltration before v0.12.0

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/20/2022

<?php

namespace My\App;

use CuyZ\Valinor\Mapper\MappingError;
use CuyZ\Valinor\Mapper\Tree\Node;
use CuyZ\Valinor\Mapper\Tree\NodeTraverser;
use CuyZ\Valinor\MapperBuilder;

require_once __DIR__ . ‘/Valinor/vendor/autoload.php’;

final class Money…

[github.com/argoproj/argo-cd] Cross-site Scripting for Argo CD SSO users

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/13/2022

Impact
All versions of Argo CD starting with 2.3.0 are vulnerable to a cross-site scripting (XSS) bug which could allow an attacker to inject arbitrary JavaScript in the /auth/callback page in a victim’s browser.
This vulnerability only affects Argo C…

[github.com/argoproj/argo-cd] Certificate verification is skipped for connections to OIDC providers

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/14/2022

Impact
All versions of Argo CD starting with v0.4.0 are vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OIDC provider.
(Note: external OIDC provider support was added in v…

[activerecord] RCE bug with Serialized Columns in Active Record

  • Posted inUncategorized
  • Posted byGitHub
  • 07/13/202207/14/2022

When serialized columns that use YAML (the default) are deserialized, Rails uses YAML.unsafe_load to convert the YAML data in to Ruby objects. If an attacker can manipulate data in the database (via means like SQL injection), then it may be possible fo…

Posts navigation

Previous Posts 1 … 15 16 17 18 19 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close