Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[org.springframework.data:spring-data-mongodb] SpEL Injection in Spring Data MongoDB

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202206/25/2022

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
References

htt…

[lettersanitizer] Improper handling of CSS at-rules in lettersanitizer

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202206/24/2022

Impact
All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule @keyframes.
This package is depended on by react-letter, therefore everyone using react-letter is also at risk.
Patches
The probl…

[github.com/weaveworks/weave-gitops] Weave GitOps leaked cluster credentials into logs on connection errors

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202206/30/2022

Impact
A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka KubeConfg, of registered Kubernetes clusters, including the service account tokens in plain text from Weave…

[rsshub] Denial of Service (DoS) vulnerability in RSSHub

  • Posted inUncategorized
  • Posted byGitHub
  • 06/23/202206/23/2022

Impact
Passing some special values to the filter and filterout parameters can cause an abnormally high CPU. Impact on the performance of the servers and RSSHub services.
Patches
It is fixed in 5c4177441417b44a6e45c3c63e9eac2504abeb5b , please update to…

[microweber/microweber] Cross-site Scripting in Microweber

  • Posted inUncategorized
  • Posted byGitHub
  • 06/23/202206/24/2022

Cross-site Scripting (XSS) – Reflected in GitHub repository microweber/microweber prior to 1.2.18.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2174
https://github.com/microweber/microweber/commit/c51285f791e48e536111cd57a9544ccbf7f33961
https…

[directus] Server-Side Request Forgery in Directus

  • Posted inUncategorized
  • Posted byGitHub
  • 06/23/202206/24/2022

Directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality, which allows a low privileged user to perform internal network port scans.
References

https://nvd.nist.gov/vuln/detai…

[nvflare] Unsafe yaml deserialization in NVFlare

  • Posted inUncategorized
  • Posted byGitHub
  • 06/23/202207/22/2022

Impact
NVFLARE contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Deni…

[nvflare] Unsafe deserialisation in the PKI implementation scheme of NVFlare

  • Posted inUncategorized
  • Posted byGitHub
  • 06/23/202207/15/2022

Impact
NVFLARE contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged network attacker to cause Remote …

[pimcore/pimcore] Improper quoting of columns when using setOrderBy() or setGroupBy() on listing classes in Pimcore

  • Posted inUncategorized
  • Posted byGitHub
  • 06/23/202206/23/2022

Impact
Pimcore offers developers listing classes to make querying data easier. This listing classes also allow to order or group the results based on one or more columns which should be quoted by default.
The actual issue is that quoting is not done p…

[shopware/shopware] Authenticated Stored Cross-site Scripting in Shopware

  • Posted inUncategorized
  • Posted byGitHub
  • 06/23/2022

Impact
Authenticated Stored XSS in Administration
Patches
We recommend updating to version 5.7.12. You can get the update to 5.7.12 regularly via the Auto-Updater or directly via the download overview.
https://www.shopware.com/de/changelog-sw5/#5-7-12
…

Posts navigation

Previous Posts 1 … 28 29 30 31 32 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close