Skip to content

Underground News

Header Image

[Nancy] Deserialization of Untrusted Data in NancyFX Nancy

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/01/2022

Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-9785
https://github.com/NancyFx/Nancy/releases/tag/v…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/02/2022

The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backups were world-readable and not r…

[org.apache.commons:commons-email] Improper Input Validation in Apache Commons Email

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/01/2022

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-9801
https://lists.apache.org/thread.html…

[openpgp] OpenPGP 1.2.0 and earlier decrypts arbitrary messages

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202206/18/2022

s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted…

ROLAND、実は恋愛経験ゼロ「観てない映画を予告編だけでレビューしてる」

  • Posted inUncategorized
  • Posted bySmartFLASH
  • 05/17/2022

ROLANDが、5月15日放送の『あざとくて何が悪いの?』(テレビ朝日系)で、恋愛経験について語った…

[com.google.gwt:gwt] Improper Neutralization of Input During Web Page Generation in Google Web Toolkit

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/09/2022

Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) before 2.5.1 RC1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References

https://nvd.nist.g…

[org.apache.axis2:axis2] Improper Input Validation in Apache Axis2

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/13/2022

Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an …

[org.codehaus.xfire:xfire-core] Improper Input Validation in XFire

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/13/2022

Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate, wh…

[org.apache.tomcat:tomcat] Improper Authentication in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/13/2022

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to …

[org.apache.tomcat:tomcat] Improper Authentication in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/13/2022

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it eas…

Posts navigation

Previous Posts 1 … 81,126 81,127 81,128 81,129 81,130 … 81,225 Next Posts

Recent Posts

  • カローラ セリカ マークII… 新型クラウンもビックリ!? 超名門トヨタがビッグネームで起こした「大変革」6選 – 自動車情報誌「ベストカー」
  • 5歳~17歳の新型コロナワクチン「接種を推奨」日本小児科学会 | NHK
  • ホラーゲーム『野狗子: Slitterhead』を開発中の外山圭一郎氏・佐藤一信氏とSIEインディーズイニシアチブ代表の吉田修平氏による対談映像が公開。
  • 花粉症に救世主? “エリート秋田杉”とは | NHK | ビジネス特集
  • 韓鶴子「女帝の正体」 13歳で文鮮明に見初められ4回帝王切開 14人出産 | 週刊文春 電子版
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close