Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[Microsoft.NETCore.App] Tampering vulnerability in .NET Core

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/09/2022

A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka “.NET Core Tampering Vulnerability.” This affects .NET Core 2.1.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-8416
https://access.redhat.com/errata…

[TelerikMvcExtensions] Improper Access Control in Telerik Extensions

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/30/2022

Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server’s web directory. NOTE: this product has been obsolete since June 2013.
References

https://nvd.nist.gov/…

[org.jenkins-ci.main:jenkins-core] Missing Authorization in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/02/2022

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of…

[org.elasticsearch:elasticsearch] Improper Access Control in Elasticsearch

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/27/2022

A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.security…

[com.itextpdf:itextpdf] Improper Restriction of XML External Entity Reference in iText

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/01/2022

The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-9096
…

[lxml] Improper Neutralization of Input During Web Page Generation in LXML

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/29/2022

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by “j a v a s c r i p t:” in Internet …

[io.undertow:undertow-core] Exposure of Sensitive Information to an Unauthorized Actor in Undertow

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/30/2022

An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain d…

[com.ning:async-http-client] Insufficient Verification of Data Authenticity in Async Http Client

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenti…

[com.ning:async-http-client] Insufficient Verification of Data Authenticity in Async Http Client

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HT…

[org.springframework.amqp:spring-amqp] Improper Authentication in Pivotal Spring-LDAP

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/01/2022

In Pivotal Spring-LDAP versions 1.3.0 – 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as …

Posts navigation

Previous Posts 1 … 70 71 72 73 74 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close