Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[com.compuware.jenkins:compuware-zadviser-api] Jenkins Compuware zAdviser API Plugin before 1.0.4 vulnerable to protection mechanism failure

  • Posted inHIGH
  • Posted byGitHub
  • 07/28/202208/11/2022

Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
References

https://nvd.nist.gov/vuln/de…

[org.jenkins-ci.plugins:rhnpush-plugin] Jenkins rhnpush-plugin does not perform a permission check in a method implementing form validation

  • Posted inMODERATE
  • Posted byGitHub
  • 07/28/202208/11/2022

Jenkins rhnpush-plugin Plugin 0.5.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker…

[org.jenkins-ci.plugins:coverity] Jenkins Coverity Plugin vulnerable to cross-site request forgery (CSRF)

  • Posted inHIGH
  • Posted byGitHub
  • 07/28/202208/11/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials sto…

[shopware/shopware] Shopware vulnerable to persistent cross site scripting (XSS) in customer module

  • Posted inseverity
  • Posted byGitHub
  • 07/28/202208/04/2022

Impact
Persistent XSS in customer module
Patches
We recommend updating to the current version 5.7.14. You can get the update to 5.7.14 regularly via the Auto-Updater or directly via the download overview.
For older versions you can use the Security Plu…

[laminas/laminas-diactoros] Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack

  • Posted inMODERATE
  • Posted byGitHub
  • 07/28/202208/11/2022

Impact
Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a Laminas\Diactoros\Uri instance associated with the incoming server request mo…

[fava] Fava vulnerable to Reflected Cross-site Scripting before v1.22.2

  • Posted inseverity
  • Posted byGitHub
  • 07/26/202208/06/2022

Cross-site Scripting (XSS) – Reflected in GitHub repository beancount/fava prior to 1.22.2.
The query_string parameter of Fava is vulnerable to reflected cross-site scripting, for which a attacker can modify any information that the user is able to mod…

[fava] Fava time and filter parameters vulnerable to reflected XSS before v1.22

  • Posted inseverity
  • Posted byGitHub
  • 07/26/202208/06/2022

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected cross-site scripting due to the lack of escaping of error messages which contained the parameters in verbatim.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2514
…

[grapesjs] grapesjs before 0.19.5 vulnerable to Cross-site Scripting

  • Posted inseverity
  • Posted byGitHub
  • 07/26/202208/06/2022

The package grapesjs before 0.19.5 is vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-21802
https://github.com/artf/grapesjs/issues/44…

[google-cloudstorage-commands] google-cloudstorage-commands Command Injection vulnerability

  • Posted inseverity
  • Posted byGitHub
  • 07/26/202208/06/2022

A command injection vulnerability affects all versions of the deprecated package google-cloudstorage-commands.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-28436
https://github.com/samradical/google-cloudstorage-commands/blob/master/index.js%2…

[git-archive] git-archive vulnerable to Command Injection via exports function

  • Posted inseverity
  • Posted byGitHub
  • 07/26/202208/06/2022

All versions of package git-archive are vulnerable to Command Injection via the exports function.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-28422
https://security.snyk.io/vuln/SNYK-JS-GITARCHIVE-1050391
https://github.com/advisories/GHSA-vq…

Posts navigation

Previous Posts 1 … 6 7 8 9 10 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close