Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[org.apache.commons:commons-compress] Uncontrolled Resource Consumption in Apache Commons Compress

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/14/2022

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many…

[github.com/protocolbuffers/protobuf] protobuf susceptible to buffer overflow

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/18/2022

protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
References

https://nvd.nist.gov/vuln/detail/CVE-2015-5237
https://github.com/google/protobuf/issues/760
https://bugzilla.redhat.com/show_bug.cgi?id=1256426
https://l…

[org.apache.zookeeper:zookeeper] Missing Authorization in Apache ZooKeeper

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/30/2022

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit chang…

[org.apache.santuario:xmlsec] Improper Input Validation in Apache Santuario XML Security

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/07/2022

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-8152
https://exchange.xforce….

[org.apache.santuario:xmlsec] Improper Input Validation in Apache Santuario XML Security

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
References

https://nvd.nist.g…

[org.opensaml:opensaml] Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) a…

[org.springframework:spring-web] Cross-Site Request Forgery in Spring Framework

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF…

[org.springframework:spring-webmvc] Cross-Site Request Forgery in Spring Framework

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CS…

[org.springframework:spring-oxm] Missing XML Validation in Spring Framework

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and con…

[org.springframework:spring-oxm] Cross-Site Request Forgery in Spring Framework

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/09/2022

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF atta…

Posts navigation

Previous Posts 1 … 72 73 74 75 76 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close