Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[ircdkit] ircdkit vulnerable to Denial of Service due to unhandled connection end event

  • Posted inseverity
  • Posted byGitHub
  • 06/04/201908/04/2022

Versions of ircdkit 1.0.3 and prior are vulnerable to a remote denial of service.
Recommendation
Upgrade to version 1.0.4.
References

https://github.com/Twipped/ircdkit/issues/1
https://github.com/Twipped/ircdkit/commit/f0cc6dc913ec17b499fa33a676bb72c…

[omniauth] Cross-site Request Forgery in OmniAuth

  • Posted inUncategorized
  • Posted byGitHub
  • 05/30/201907/16/2022

The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the use…

[mysql] mysql Node.JS Module Vulnerable to Remote Memory Exposure

  • Posted inseverity
  • Posted byGitHub
  • 05/23/201908/04/2022

Versions of mysql before 2.14.0 are vulnerable to remove memory exposure.
Affected versions of mysql package allocate and send an uninitialized memory over the network when a number is provided as a password.
Only mysql running on Node.js versions belo…

[selenium-binaries] selenium-binaries downloads resources over HTTP

  • Posted inseverity
  • Posted byGitHub
  • 02/19/201908/04/2022

Versions of selenium-binaries prior to 0.15.0 insecurely download an executable over an unencrypted HTTP connection.
In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable …

[pyspark] Moderate severity vulnerability that affects pyspark

  • Posted inUncategorized
  • Posted byGitHub
  • 02/08/201906/07/2022

When using PySpark , it’s possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.
References

https://n…

[System.ServiceModel.Security] Improper Certificate Validation in Microsoft .NET Framework components

  • Posted inHIGH
  • Posted byGitHub
  • 10/17/201808/11/2022

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka “.NET Security Fe…

[ansible] Ansible is vulnerable to an improper input validation in Ansible’s handling of data sent from client systems

  • Posted inUncategorized
  • Posted byGitHub
  • 10/11/201807/16/2022

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible’s handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the …

[electron] Electron webPreferences vulnerability can be used to perform remote code execution

  • Posted inUncategorized
  • Posted byGitHub
  • 08/24/201808/03/2022

GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and “nativeWindowOpen: true” or “sandbox: true” options, is affected by a webPreferences vulnerability that can be leveraged to perform remote code e…

[metascraper] metascraper before v5.2.0 vulnerable to stored cross-site scripting

  • Posted inseverity
  • Posted byGitHub
  • 08/09/201808/04/2022

Versions of metascraper prior to 5.2.0 are vulnerable to stored cross-site scripting (XSS).
Recommendation
Upgrade to version 5.2.0 or later.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-3773
https://hackerone.com/reports/309367
https://www.np…

[confire] Critical severity vulnerability that affects confire

  • Posted inUncategorized
  • Posted byGitHub
  • 07/19/201807/26/2022

An exploitable vulnerability exists in the YAML parsing functionality in config.py in Confire 0.2.0. Due to the user-specific configuration being loaded from “~/.confire.yaml” using the yaml.load function, a YAML parser can execute arbitrary Python com…

Posts navigation

Previous Posts 1 … 90 91 92 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close