Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[scratchpad] move_elements can double-free objects on panic

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/17/2022

An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free upon a panic in a user-provided f function.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-28031
https://rustsec.org/advisor…

[vscode-npm-script] Remote code execution in vscode-npm-script

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202207/20/2022

Visual Studio Code npm-script Extension Remote Code Execution Vulnerability
References

https://nvd.nist.gov/vuln/detail/CVE-2021-26700
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26700
https://github.com/advisories/GHSA…

[jsdom] Insufficient Granularity of Access Control in JSDom

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/23/2022

JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious web page when script execution is enabled.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-20066
https://www.tenable.com/securit…

[qwutils] insert_slice_clone can double drop if Clone panics.

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/17/2022

An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-26954
https://rustsec.org/advisories/RUSTSEC-2021-0018.ht…

[org.elasticsearch:elasticsearch] Insertion of Sensitive Information into Log File in Elasticsearch

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authenticati…

[org.jetbrains.kotlin:kotlin-stdlib] Incorrect Default Permissions in JetBrains Kotlin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
References

https://nvd.nist.gov/vuln/detail/C…

[smallvec] Buffer overflow in SmallVec::insert_many

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/17/2022

An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-25900
https://rustsec.org/advisories/RUSTSE…

[jupyterhub] Cross-Site Request Forgery in JupyterHub

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36191
https://github.com/jupyte…

[@strikeentco/set] Prototype pollution in @strikeentco/set

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/18/2022

Prototype pollution vulnerability in ‘@strikeentco/set’ version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-28267
https://github.com/strikeentco/set/com…

[CKEditor4] Improper Neutralization of Input During Web Page Generation in CKEditor4

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
References

https://nvd…

Posts navigation

Previous Posts 1 … 50 51 52 53 54 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close