Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[org.apache.kylin:kylin] Apache Kylin vulnerable to Command injection by Diagnosis Controller

  • Posted inHIGH
  • Posted byWpmaster
  • 12/30/202201/03/2023

Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-44621
https://lists.apache.org/thread/7ctchj24dofgsj9g1rg1245cms9myb34
https://github.com/…

[github.com/go-macaron/csrf] Macaron csrf missing encryption and has sensitive cookies in HTTP session without secure attribute

  • Posted inHIGH
  • Posted byWpmaster
  • 12/30/202201/10/2023

A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown functionality of the file csrf.go. The manipulation of the argument Generate leads to sensitive cookie without secure attribute. The attack …

[org.apache.kylin:kylin] Apache Kylin vulnerable to Command injection by Useless configuration

  • Posted inHIGH
  • Posted byWpmaster
  • 12/30/202201/03/2023

In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.
References

https://nvd.nist.gov/vuln…

[json5] Prototype Pollution in JSON5 via Parse Method

  • Posted inHIGH
  • Posted byWpmaster
  • 12/29/202201/04/2023

The parse method of the JSON5 library before and including version 2.2.1 does not restrict parsing of keys named __proto__, allowing specially crafted strings to pollute the prototype of the resulting object.
This vulnerability pollutes the prototype o…

[github.com/fkie-cad/yapscan] Yapscan’s report receiver server vulnerable to path traversal and log injection

  • Posted inHIGH
  • Posted byWpmaster
  • 12/29/2022

Impact
If you make use of the report receiver server (experimental), a client may be able to forge requests such that arbitrary files on the host can be overwritten (subject to permissions of the yapscan server), leading to loss of data. This is partic…

[com.thoughtworks.xstream:xstream] XStream can cause Denial of Service via stack overflow

  • Posted inHIGH
  • Posted byWpmaster
  • 12/29/202212/29/2022

Impact
The vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream.
Patches
XStream 1.4.20 handles the stack overflow and raises…

[github.com/usememos/memos] usememos/memos Improper Privilege Management vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 12/29/202201/10/2023

Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4808
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/bounties/11…

[github.com/usememos/memos] usememos/memos Improper Access Control vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 12/29/202201/11/2023

usememos/memos 0.9.0 and prior is vulnerable to full account takeover via changing user name, email address, and display name.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4809
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a17…

[github.com/usememos/memos] usememos/memos makes Incorrect Use of Privileged APIs

  • Posted inHIGH
  • Posted byWpmaster
  • 12/29/202201/11/2023

In usememos/memos 0.9.0 and prior, a user with login permission can delete all notes of the whole application via API DELETE https://demo.usememos.com/api/memo/$idnote. The vulnerability will lose all user notes data throughout the system, causing dama…

[github.com/usememos/memos] usememos/memos Improper Access Control vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 12/29/202201/11/2023

usememos/memos 0.9.0 and prior is vulnerable to Improper Access Control.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4803
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/bounties/0fba72b9-db…

Posts navigation

Previous Posts 1 … 9 10 11 12 13 … 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close