Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[fava] Fava before 1.22.3 vulnerable to reflected cross-site scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 08/02/202208/11/2022

Fava before 1.22.3 is vulnerable to reflected cross-site scripting due to improper validation on filter conversion.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2589
https://github.com/beancount/fava/commit/68bbb6e39319deb35ab9f18d0b6aa9fa7047…

[node-fetch] node-fetch Inefficient Regular Expression Complexity

  • Posted inseverity
  • Posted byGitHub
  • 08/02/202208/05/2022

node-fetch is a light-weight module that brings window.fetch to node.js.
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in the isOriginPotentiallyTrustworthy() function in referrer.js, when processing a…

[github.com/graphql-go/graphql] graphql-go through 0.8.0 has infinite recursion in the type definition parser

  • Posted inHIGH
  • Posted byGitHub
  • 08/02/202208/11/2022

graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37315
https://github.com/graphql-go/graphql/issues/637
https://github.com/advisories/GHSA-h3qm-jrr…

[github.com/runatlantis/atlantis/server/controllers/events] Atlantis Events prior to 0.19.7 vulnerable to Timing Attack

  • Posted inseverity
  • Posted byGitHub
  • 07/30/202208/09/2022

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow…

[org.eclipse.californium:californium-core] Eclipse Californium denial of service (DoS) via Datagram Transport Layer Security (DTLS) handshake on parameter mismatch

  • Posted inHIGH
  • Posted byGitHub
  • 07/30/202208/11/2022

In Eclipse Californium versions 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest. Especially, if used with certificate based cipher suites, that re…

[juniper] Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow

  • Posted inUncategorized
  • Posted byGitHub
  • 07/30/202207/30/2022

GraphQL behaviour
Nested fragment in GraphQL might be quite hard to handle depending on the implementation language.
Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
# I…

[Flask-AppBuilder] Flask-AppBuilder before v4.1.3 allows inference of sensitive information through query strings

  • Posted inLOW
  • Posted byGitHub
  • 07/30/202208/11/2022

Impact
An authenticated Admin user could craft HTTP requests to filter users by their salted and hashed passwords strings. These filters could be made by using partial hashed password strings. The response would not include the hashed passwords, but an…

[prestashop/prestashop] PrestaShop eval injection possible if shop vulnerable to SQL injection

  • Posted inseverity
  • Posted byGitHub
  • 07/30/202208/04/2022

Impact
Eval injection possible if the shop is vulnerable to an SQL injection.
Patches
The problem is fixed in version 1.7.8.7
Workarounds
Delete the MySQL Smarty cache feature by removing these lines in the file config/smarty.config.inc.php lines 43-46…

[scrapy] Scrapy before v2.6.2 and v1.8.3 vulnerable to one proxy sending credentials to another

  • Posted inUncategorized
  • Posted byGitHub
  • 07/30/202207/30/2022

Impact
When the built-in HTTP proxy downloader middleware processes a request with proxy metadata, and that proxy metadata includes proxy credentials, the built-in HTTP proxy downloader middleware sets the Proxy-Authentication header, but only if that …

[mezzio/mezzio-swoole] mezzio-swoole Applications Using Diactoros Vulnerable to HTTP Host Header Attack

  • Posted inUncategorized
  • Posted byGitHub
  • 07/30/202207/30/2022

Impact
mezzio-swoole applications using Diactoros for their PSR-7 implementation, and which are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a Laminas\Diactoros\Uri instanc…

Posts navigation

Previous Posts 1 2 3 4 5 6 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close