Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[dot] Improper Control of Generation of Code in doT

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/23/2022

The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-81…

[blamer] Improper Neutralization of Special Elements used in an OS Command in Blamer

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/29/2022

Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-10807
https://snyk.io/vuln/SNYK-JS-BLA…

[org.jenkins-ci.plugins:git] Improper Neutralization of Input During Web Page Generation in Jenkins Git Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2136
…

[com.mobileenerlytics.eagle.tester:eagle-tester] Plaintext Storage of a Password in Jenkins Eagle Tester Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
References

https://nvd.nist.gov/vuln/detail/CVE-2…

[org.jenkins-ci.plugins.workflow:workflow-cps] Improper Input Validation in Jenkins Pipeline: Groovy Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed methods.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2109
https://jenkins.io/security/advisory…

[org.jenkins-ci.plugins:script-security] Improper Input Validation in Jenkins Script Security Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
References

https://nvd.ni…

[codecov] Improper Neutralization of Special Elements in Output Used by a Downstream Component in Codecov

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/28/2022

Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the “gcov-args” argument.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-7596
https://snyk.io/vuln/SNYK-JS-CODECOV-543183
https://github.com/advisories/GHS…

[waitress] Inconsistent Interpretation of HTTP Requests in Waitress

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/28/2022

Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Cont…

[Microsoft.AspNetCore.App] Denial of service in ASP.NET Core

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202207/08/2022

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka ‘ASP.NET Core Denial of Service Vulnerability’.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-0602
https://access.redhat.com/errata/RHSA-2020:0130
h…

[Microsoft.AspNetCore.Http.Connections] Remote code execution in ASP.NET Core

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202207/08/2022

A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka ‘ASP.NET…

Posts navigation

Previous Posts 1 … 54 55 56 57 58 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close