Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[window-control] window-control vulnerable to Command Injection due to improper input sanitization

  • Posted inHIGH
  • Posted byWpmaster
  • 01/05/202301/07/2023

window-control is an npm package that provides tools to manage window focus. Versions before 1.4.5 are vulnerable to Command Injection via the sendKeys function due to improper input sanitization.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2…

[io.gravitee.apim:gravitee-api-management] Gravitee API Management contains Path Traversal

  • Posted inHIGH
  • Posted byWpmaster
  • 01/04/202301/11/2023

This CVE addresses the partial fix for CVE-2019-25075
Gravitee API Management before 3.15.13 allows path traversal through HTML injection. A certain HTML injection combined with path traversal in the Email service in Gravitee API Management before 3.15…

[io.apiman:apiman-manager-api-rest-impl] Apiman has potential permissions bypass

  • Posted inHIGH
  • Posted byWpmaster
  • 01/03/202301/03/2023

Impact
Incorrect default permissions for certain read-only resources in the Apiman 1.5.7.Final through 2.2.3.Final in the Apiman Manager REST API allows a remote authenticated attacker to access information and resources in an Apiman Organizations they…

[sumocoders/framework-user-bundle] FrameworkUserBundle Generates Error Message Containing Sensitive Information

  • Posted inHIGH
  • Posted byWpmaster
  • 01/03/202301/11/2023

A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Resources/views/Security/login.html.twig. The manipulation leads to information …

[string-kit] string-kit Inefficient Regular Expression Complexity vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 01/02/202301/11/2023

A vulnerability classified as problematic was found in cronvel string-kit up to 0.12.7. This vulnerability affects the function naturalSort of the file lib/naturalSort.js. The manipulation leads to inefficient regular expression complexity. The attack …

[io.apiman:apiman-gateway-platforms-vertx] Apiman Vert.x Gateway has Transitive Hazelcast connection caching issue

  • Posted inHIGH
  • Posted byWpmaster
  • 12/31/2022

Impact
If you are using the Apiman Vert.x Gateway prior to Apiman 3.0.0.Final, a connection caching issue in Hazelcast could allow an unauthenticated, remote attacker to access and manipulate data in the cluster with another authenticated connection’s …

[github.com/usememos/memos] usememos/memos vulnerable to Improper Handling of Insufficient Permissions or Privileges

  • Posted inHIGH
  • Posted byWpmaster
  • 12/31/202201/05/2023

Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4863
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53…

[io.metersphere:metersphere] Path Traversal In MeterSpere leads to upload file to any path

  • Posted inHIGH
  • Posted byWpmaster
  • 12/31/202212/31/2022

Summary
MeterSphere allow users to upload file, but not check the file name, may lead to upload file to any path if the file name in upload request is falsified.
Details
Metersphere’s FileUtils.java didn’t check the filePath.
public static void cre…

[com.thoughtworks.xstream:xstream] XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow

  • Posted inHIGH
  • Posted byWpmaster
  • 12/31/2022

Impact
The vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream.
Patches
XStream 1.4.20 handles the stack overflow and raises…

[github.com/ElrondNetwork/elrond-go] Elrond-GO processing: fallback search of SCRs when not found in the main cache

  • Posted inHIGH
  • Posted byWpmaster
  • 12/31/202212/31/2022

Impact
Processing issue, nodes are affected when trying to process a cross-shard relayed transaction with a smart contract deploy transaction data. The problem was a bad correlation between the transaction caches and the processing component. If the ab…

Posts navigation

Previous Posts 1 … 8 9 10 11 12 … 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close