Skip to content

Underground News

Header Image

[org.apache.cxf:cxf] Remote web-service operation execution in Apache CXF

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/14/2022

Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
References

https://nvd.n…

[org.apache.cxf:cxf-rt-frontend-jaxrs] Missing XML Validation in Apache CXF

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/09/2022

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes…

[org.apache.cxf:cxf-core] Cleartext Transmission of Sensitive Information in Apache CXF

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers t…

[nnabla] Sony Neural Network Libraries reliance on untrusted inputs prior to v1.0.10

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/29/2022

nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) prior to v1.0.10 relies on the HOME environment variable, which might be untrusted.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-10844
https://github.com/sony/nnabla/…

[org.apache.commons:commons-compress] Uncontrolled Resource Consumption in Apache Commons Compress

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/14/2022

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many…

[github.com/protocolbuffers/protobuf] protobuf susceptible to buffer overflow

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/18/2022

protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
References

https://nvd.nist.gov/vuln/detail/CVE-2015-5237
https://github.com/google/protobuf/issues/760
https://bugzilla.redhat.com/show_bug.cgi?id=1256426
https://l…

[org.apache.zookeeper:zookeeper] Missing Authorization in Apache ZooKeeper

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/30/2022

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit chang…

[org.apache.santuario:xmlsec] Improper Input Validation in Apache Santuario XML Security

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
References

https://nvd.nist.g…

[org.apache.santuario:xmlsec] Improper Input Validation in Apache Santuario XML Security

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/07/2022

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-8152
https://exchange.xforce….

[org.opensaml:opensaml] Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/08/2022

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) a…

Posts navigation

Previous Posts 1 … 81,139 81,140 81,141 81,142 81,143 … 81,225 Next Posts

Recent Posts

  • カローラ セリカ マークII… 新型クラウンもビックリ!? 超名門トヨタがビッグネームで起こした「大変革」6選 – 自動車情報誌「ベストカー」
  • 5歳~17歳の新型コロナワクチン「接種を推奨」日本小児科学会 | NHK
  • ホラーゲーム『野狗子: Slitterhead』を開発中の外山圭一郎氏・佐藤一信氏とSIEインディーズイニシアチブ代表の吉田修平氏による対談映像が公開。
  • 花粉症に救世主? “エリート秋田杉”とは | NHK | ビジネス特集
  • 韓鶴子「女帝の正体」 13歳で文鮮明に見初められ4回帝王切開 14人出産 | 週刊文春 電子版
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close