Skip to content

Underground News

Header Image

[System.Private.Uri] Improper Input Validation in .Net Framework API’s

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/09/2022

A vulnerability exists in certain .Net Framework API’s and Visual Studio in the way they parse URL’s, aka ‘.NET Framework and Visual Studio Spoofing Vulnerability’.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-0657
https://access.redhat.com/er…

[org.apache.tomcat:tomcat] Directory Traversal in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/10/2022

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to byp…

[select2] Improper Neutralization of Input During Web Page Generation in Select2

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/07/2022

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[org.apache.activemq:activemq-client] Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/07/2022

Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References

https://nvd.nist.gov/vul…

[jupyter-notebook] Improper Neutralization of Input During Web Page Generation in Jupyter Notebook

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/24/2022

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated w…

[org.apache.tomcat:tomcat] Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/08/2022

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain “Tomcat internals” information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML doc…

[org.apache.tomcat:tomcat] Improper Access Control in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/07/2022

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers …

[org.apache.tomcat:tomcat] Insufficient Verification of Data Authenticity in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/01/2022

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poiso…

[suds] Improper Link Resolution Before File Access in Suds

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/09/2022

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
References

https://nvd.nist.gov/vuln/…

[org.wildfly.core:wildfly-server] Improper Limitation of a Pathname to a Restricted Directory in WildFly

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/30/2022

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the ‘Zip Slip’ vulnerability.
References

https:/…

Posts navigation

Previous Posts 1 … 81,133 81,134 81,135 81,136 81,137 … 81,225 Next Posts

Recent Posts

  • カローラ セリカ マークII… 新型クラウンもビックリ!? 超名門トヨタがビッグネームで起こした「大変革」6選 – 自動車情報誌「ベストカー」
  • 5歳~17歳の新型コロナワクチン「接種を推奨」日本小児科学会 | NHK
  • ホラーゲーム『野狗子: Slitterhead』を開発中の外山圭一郎氏・佐藤一信氏とSIEインディーズイニシアチブ代表の吉田修平氏による対談映像が公開。
  • 花粉症に救世主? “エリート秋田杉”とは | NHK | ビジネス特集
  • 韓鶴子「女帝の正体」 13歳で文鮮明に見初められ4回帝王切開 14人出産 | 週刊文春 電子版
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close