Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[github.com/usememos/memos] usememos/memos Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/31/202201/05/2023

Cross-site Scripting (XSS) – Stored in GitHub repository usememos/memos prior to 0.9.1.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4865
https://github.com/usememos/memos/commit/7670c9536000bb32c6345d4906a91268dcddd5fc
https://huntr.dev/bount…

[github.com/usememos/memos] usememos/memos vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/31/202201/05/2023

Cross-site Scripting (XSS) – Stored in GitHub repository usememos/memos prior to 0.9.1.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4866
https://github.com/usememos/memos/commit/7670c9536000bb32c6345d4906a91268dcddd5fc
https://huntr.dev/bount…

[mellium.im/sasl] Mellium vulnerable to authentication failure or insufficient randomness used during authentication

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/31/202201/04/2023

An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty). This causes authenti…

[froxlor/froxlor] Froxlor vulnerable to Argument Injection

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/31/202201/11/2023

Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4864
https://github.com/froxlor/froxlor/commit/f2485ecd9aab8da544b5e12891d82ae6fcff5fc7
https://huntr.dev/bounties/b7140…

[prettytable-rs] prettytable-rs: Force cast a &Vec to &[T] may lead to undefined behavior

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/31/202201/07/2023

In function Table::as_ref, a reference of vector is force cast to slice. There are multiple problems here:

To guarantee the size is correct, we have to first do Vec::shrink_to_fit. The function requires a mutable reference, so we have to force cast fr…

[github.com/kubernetes-sigs/aws-efs-csi-driver] efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/31/2022

Impact
A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port f…

[hyper-staticfile] hyper-staticfile’s location header incorporates user input, allowing open redirect

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/31/202201/07/2023

When hyper-staticfile performs a redirect for a directory request (e.g. a request for /dir that redirects to /dir/), the Location header value was derived from user input (the request path), simply appending a slash. The intent was to perform an origin…

[github.com/gotify/server] gotify/server vulnerable to Cross-site Scripting in the application image file upload

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202212/30/2022

Impact
The XSS vulnerability allows authenticated users to upload .html files. With that, an attacker could execute client side scripts if another user opened a link, such as:
https://push.example.org/image/[alphanumeric string].html

An attacker could…

[github.com/usememos/memos] usememos/memos vulnerable to Improper Verification of Source of a Communication Channel

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202201/11/2023

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4848
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948…

[github.com/usememos/memos] usememos/memos Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202212/31/2022

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4850
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948
https://huntr.dev/bounti…

Posts navigation

Previous Posts 1 … 14 15 16 17 18 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close