Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[org.dspace:dspace-jspui] JSPUI’s controlled vocabulary feature vulnerable to Open Redirect before v6.4 and v5.11

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

Impact
The JSPUI controlled vocabulary servlet is vulnerable to an open redirect attack, where an attacker can craft a malicious URL that looks like a legitimate DSpace/repository URL. When that URL is clicked by the target, it redirects them to a sit…

[org.dspace:dspace-jspui] JSPUI Possible Cross Site Scripting in “Request a Copy” Feature

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

Impact
The JSPUI “Request a Copy” feature does not properly escape values submitted and stored from the “Request a Copy” form. This means that item requests could be vulnerable to XSS attacks. This vulnerability only impacts the JSPUI.
This vulnerabi…

[org.dspace:dspace-jspui] Cross Site Scripting (XSS) possible in JSPUI spellcheck and autocomplete tools

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

Impact
The JSPUI spellcheck “Did you mean” HTML escapes the data-spell attribute in the link, but not the actual displayed text. Similarly, the JSPUI autocomplete HTML does not properly escape text passed to it. Both are vulnerable to XSS. This vulne…

[org.dspace:dspace-xmlui] XMLUI’s metadata of withdrawn Items is exposed to anonymous users

  • Posted inseverity
  • Posted byGitHub
  • 08/06/2022

Impact
Metadata on a withdrawn Item is exposed via the XMLUI “mets.xml” object, as long as you know the handle/URL of the withdrawn Item. This vulnerability only impacts the XMLUI.
However, this vulnerability is very low severity as Item metadata does …

[org.dspace:dspace-jspui] JSPUI’s “Internal System Error” page prints exceptions and stack traces without sanitization

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

Impact
When an “Internal System Error” occurs in the JSPUI, then entire exception (including stack trace) is available. Information in this stacktrace may be useful to an attacker in launching a more sophisticated attack. This vulnerability only impac…

[@solana/pay] Solana Pay Vulnerable to Weakness in Transfer Validation Logic

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

Description
When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied validateTransfer function. An edge case regarding this mechanism could caus…

[drupal/core] Drupal core Information Disclosure vulnerability

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating derivative images using the image styles system.
Access to a non-public file is checked only if it is …

[untangle] untangle before 1.2.1 vulnerable to XML Entity Expansion

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

Impact
An attacker may be able to cause a denial-of-service (DoS) condition on the server on which the product is running. This affects untangle versions up to and including 1.2.0
Patches
The problem has been fixed with version 1.2.1
Workarounds
None
R…

[untangle] untangle before 1.2.1 vulnerable to Improper Restriction of XML External Entity Reference

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

Impact
An attacker may be able to read the contents of local files. This affects untangle versions up to and including 1.2.0
Patches
The problem has been fixed with version 1.2.1
Workarounds
None
References
https://jvn.jp/en/jp/JVN30454777/
For more in…

[next-auth] next-auth before v4.10.2 and v3.29.9 leaks excessive information into log

  • Posted inseverity
  • Posted byGitHub
  • 08/06/202208/06/2022

Impact
An information disclosure vulnerability in next-auth before v4.10.2 and v3.29.9 allows an attacker with log access privilege to obtain excessive information such as an identity provider’s secret in the log (which is thrown during OAuth error han…

Posts navigation

Previous Posts 1 2 3 4 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close