Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[salt] Minion identity not validated in saltstack

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/16/2022

Salt (aka SaltStack) before 0.15.0 through 0.17.0 allows remote authenticated minions to impersonate arbitrary minions via a crafted minion with a valid key.
References

https://nvd.nist.gov/vuln/detail/CVE-2013-4439
https://github.com/saltstack/salt/p…

[org.jgroups:jgroups] Exposure of Sensitive Information to an Unauthorized Actor in JGroup

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/09/2022

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
References

https://nvd….

[org.apache.solr:solr-core] Improper Restriction of XML External Entity Reference in Apache Solr

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/13/2022

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to…

[org.apache.geronimo.framework:geronimo-jmx-remoting] Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/28/2022

The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execut…

[org.apache.solr:solr-core] XML Injection in Apache Solr

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/08/2022

The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an enti…

[org.directwebremoting:dwr] Improper Neutralization of Input During Web Page Generation in Direct Web Remoting

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/07/2022

Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-5…

[io.undertow:undertow-core] Improper Limitation of a Pathname to a Restricted Directory in JBoss Undertow

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/07/2022

Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.
References

ht…

[org.drools:drools-core] Improper Input Validation in Drools and jBPM

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/07/2022

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-8125
https…

[org.apache.solr:solr-core] Improper Limitation of a Pathname to a Restricted Directory in Apache Solr

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/08/2022

Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to…

[org.owasp.esapi:esapi] Missing Cryptographic Step in OWASP Enterprise Security API for Java

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/08/2022

The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attac…

Posts navigation

Previous Posts 1 … 58 59 60 61 62 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close