Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[org.jenkins-ci.plugins:google-login] Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification

  • Posted inUncategorized
  • Posted byGitHub
  • 07/08/202207/20/2022

The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
Refe…

[org.apache.druid:druid] Cross site scripting in Apache Druid

  • Posted inUncategorized
  • Posted byGitHub
  • 07/08/202207/09/2022

In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-447…

[org.apache.druid:druid] Clickjacking in Apache Druid

  • Posted inUncategorized
  • Posted byGitHub
  • 07/08/202207/09/2022

In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-28889
ht…

[snipe/snipe-it] Snipe-IT 6.0.2 vulnerable to Cross-site Scripting via arbitrary file upload in Update Branding Settings

  • Posted inUncategorized
  • Posted byGitHub
  • 07/08/202207/22/2022

An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-32060
https://grimthereaperteam.med…

[snipe/snipe-it] Snipe-IT 6.0.2 vulnerable to Cross-site Scripting

  • Posted inUncategorized
  • Posted byGitHub
  • 07/08/202207/22/2022

An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-32061
https://gri…

[org.eclipse.lyo:lyo-parent] XML External Entity Reference in Eclipse Lyo

  • Posted inUncategorized
  • Posted byGitHub
  • 07/08/202207/20/2022

In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.
References

https://nvd.nist.gov…

[apache-superset] Apache Superset before 1.5.1 allows authenticated users to access metadata for datasets they have no permission on

  • Posted inUncategorized
  • Posted byGitHub
  • 07/07/202207/16/2022

Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[github.com/ipfs/go-ipfs] DOS and excessive memory usage when passing untrusted user input to to dag import

  • Posted inUncategorized
  • Posted byGitHub
  • 07/07/202207/16/2022

Impact
go-ipfs nodes crash when trying to import certain malformed CAR files due to an issue in the go-car dependency. This impacts nodes running ipfs dag import on untrusted user inputs, for example, pinning services with a car ingest endpoint.
This i…

[openssl-src] AES OCB fails to encrypt some bytes

  • Posted inUncategorized
  • Posted byGitHub
  • 07/07/202207/26/2022

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised
implementation will not encrypt the entirety of the data under some
circumstances. This could reveal sixteen bytes of data that was
preexisting in the memory that wasn’t written…

[parse-server] Protected fields exposed via LiveQuery

  • Posted inUncategorized
  • Posted byGitHub
  • 07/07/202207/07/2022

Impact
Parse Server LiveQuery does not remove protected fields in classes, passing them to the client.
Patches
The LiveQueryController now removes protected fields from the client response.
Workarounds
Use Parse.Cloud.afterLiveQueryEvent to manually re…

Posts navigation

Previous Posts 1 … 18 19 20 21 22 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close