Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[github.com/weaveworks/weave-gitops] GitOps Run allows for Kubernetes workload injection

  • Posted inHIGH
  • Posted byWpmaster
  • 01/10/202301/10/2023

Impact
A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster’s resources.
GitOps run has a local S3 bucket which it uses for synchronising files that are later applied against a Kubernetes cluster. Its endpoint…

[luxon] Luxon Inefficient Regular Expression Complexity vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 01/09/202301/10/2023

Impact
Luxon’s `DateTime.fromRFC2822() has quadratic (N^2) complexity on some specific inputs. This causes a noticeable slowdown for inputs with lengths above 10k characters. Users providing untrusted data to this method are therefore vulnerable to (Re…

[debug] debug Inefficient Regular Expression Complexity vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 01/09/202301/29/2023

A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to v…

[wifey] wifey vulnerable to Command Injection due to improper input sanitization

  • Posted inHIGH
  • Posted byWpmaster
  • 01/09/202301/10/2023

All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-25890
https://security.snyk.io/vuln/SNYK-JS-WIFEY-3175615
https:/…

[terminal-kit] terminal-kit Inefficient Regular Expression Complexity vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 01/08/202301/28/2023

A vulnerability classified as problematic has been found in cronvel terminal-kit up to 2.1.7. Affected is an unknown function. The manipulation leads to inefficient regular expression complexity. Upgrading to version 2.1.8 can address this issue. The n…

[org.http4s:http4s-core] Http4s improperly parses User-Agent and Server headers

  • Posted inHIGH
  • Posted byWpmaster
  • 01/07/202301/07/2023

Impact
The User-Agent and Server header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers.
v0.21.x
val unsafe: Option…

[exec-local-bin] exec-local-bin vulnerable to Command Injection

  • Posted inHIGH
  • Posted byWpmaster
  • 01/06/202301/10/2023

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-25923
https://github.com/saeedseyf…

[@mattkrick/sanitize-svg] @mattkrick/sanitize-svg vulnerable to Cross-Site Scripting (XSS)

  • Posted inHIGH
  • Posted byWpmaster
  • 01/05/202301/05/2023

Impact
The sanitize-svg package uses a deny-list-pattern to sanitize SVGs to prevent cross-site scripting (XSS). In doing so, literal <script>-tags and on-event handlers were detected:
[…]
const svgEl = div.firstElementChild!
const attribut…

[pghero] PgHero Allows Information Disclosure Through EXPLAIN Feature

  • Posted inHIGH
  • Posted byWpmaster
  • 01/05/202301/12/2023

PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on …

[@uniswap/universal-router] Uniswap Universal Router Incorrect Authorization vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 01/05/202301/27/2023

Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-48216
https://github.com/Uniswap/universal-router/pull/189
https://github.com/Uniswap/universal-r…

Posts navigation

Previous Posts 1 … 7 8 9 10 11 … 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close