Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[github.com/usememos/memos] usememos/memos vulnerable to account takeover due to improper access control

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202212/27/2022

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Versions prior to 0.9.0 improperly maintain access control allowing an attacker to take over an account by changing header values in the HTTP request.
R…

[github.com/usememos/memos] usememos/memos vulnerable due to improper authentication

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202212/27/2022

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Memos versions prior to 0.9.0 are vulnerable to improper authorization, which can allow a user to modify the nickname, username and email of other users…

[github.com/usememos/memos] usememos/memos makes Incorrect Use of Privileged APIs

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202212/31/2022

Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4687
https://github.com/usememos/memos/commit/dca35bde877aab6e64ef51b52e590b5d48f692f9
https://huntr.dev/bounties…

[github.com/usememos/memos] usememos/memos Improper Authentication vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202212/31/2022

Improper Authentication in GitHub repository usememos/memos prior to 0.9.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4686
https://github.com/usememos/memos/commit/dca35bde877aab6e64ef51b52e590b5d48f692f9
https://huntr.dev/bounties/caa0b22c…

[future] Python Charmers Future denial of service vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202201/20/2023

An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server. This issue has been patched in version 0.18.3.
References

https://nvd.nist.g…

[wheel] pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202212/27/2022

Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerab…

[setuptools] pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202212/27/2022

Python Packaging Authority (PyPA)’s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package…

[codeigniter4/framework] CodeIgniter4 Potential Session Handlers Vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202201/06/2023

Impact
When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to DatabaseHandler, MemcachedHandler, or RedisHandler, then if an attacker gets one session cookie (e.g., …

[codeigniter4/framework] CodeIgniter4 allows spoofing of IP address when using proxy

  • Posted inHIGH
  • Posted byWpmaster
  • 12/23/202201/08/2023

Impact
This vulnerability may allow attackers to spoof their IP address when your server is behind a reverse proxy.
Patches
Upgrade to v4.2.11 or later, and configure Config\App::$proxyIPs.
Workarounds
Do not use $request->getIPAddress().
References…

[github.com/destinygg/chat] destiny.gg chat vulnerable to cross-site request forgery

  • Posted inHIGH
  • Posted byWpmaster
  • 12/22/202212/31/2022

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocket.Upgrader of the file main.go. The manipulation leads to cross-site request forgery. The attack may…

Posts navigation

Previous Posts 1 … 12 13 14 15 16 … 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close