Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[co.fs2:fs2-io] fs2-io skips mTLS client verification

  • Posted inseverity
  • Posted byGitHub
  • 07/30/202208/04/2022

Impact
When establishing a server-mode TLSSocket using fs2-io on Node.js, the parameter requestCert = true is ignored, peer certificate verification is skipped, and the connection proceeds.
The vulnerability is limited to:

fs2-io running on Node.js. T…

[async-graphql] async-graphql / async-graphql – @DOS GraphQL Nested Fragments overflow

  • Posted inUncategorized
  • Posted byGitHub
  • 07/30/2022

Impact
Executing deeply nested queries may cause stack overflow.
Patches
Upgrade to v4.0.6
References

https://github.com/async-graphql/async-graphql/security/advisories/GHSA-xq3c-8gqm-v648
https://github.com/async-graphql/async-graphql/commit/521769b8…

[feehi/cms] Feehi CMS Cross-site Scripting

  • Posted inseverity
  • Posted byGitHub
  • 07/29/202208/06/2022

A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.
References

https://nvd.nist.gov/vuln/…

[org.apache.calcite.avatica:avatica-core] Apache Calcite Avatica JDBC driver arbitrary code execution

  • Posted inseverity
  • Posted byGitHub
  • 07/29/202208/06/2022

Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via httpclient_impl connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which ca…

[mongoose] Prototype pollution Schema.path in automattic/mongoose

  • Posted inseverity
  • Posted byGitHub
  • 07/29/202208/04/2022

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.\n\nAffected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the sch…

[reqmon] WMAgent arbitrary code execution via a crafted dbs-client package

  • Posted inseverity
  • Posted byGitHub
  • 07/29/202208/06/2022

WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-34558
https…

[feehi/cms] Feehi CMS arbitrary code execution via crafted PHP file

  • Posted inseverity
  • Posted byGitHub
  • 07/28/202208/06/2022

An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-34971
https://github.com/liufee/cms…

[org.jenkins-ci.plugins:git] Jenkins Git Plugin before 4.11.4 provides unauthenticated attackers information about the existence of jobs

  • Posted inMODERATE
  • Posted byGitHub
  • 07/28/202208/11/2022

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-36884
…

[org.jenkins-ci.plugins:git] Jenkins Git Plugin before 4.11.4 is missing a permission check

  • Posted inHIGH
  • Posted byGitHub
  • 07/28/202208/11/2022

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
Reference…

[org.jenkins-ci.plugins:git-client] Jenkins Git client plugin 3.11.0 does not perform SSH host key verification

  • Posted inHIGH
  • Posted byGitHub
  • 07/28/202208/11/2022

Jenkins Git client plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks. Git client plugin 3.11.1 provides strategies for performing host key verification f…

Posts navigation

Previous Posts 1 … 3 4 5 6 7 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close