Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[github.com/cri-o/cri-o] CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/2022

Impact
It is possible to craft an environment variable with newlines to add entries to a container’s /etc/passwd. It is possible to circumvent admission validation of username/UID by adding such an entry.
Note: because the pod author is in control of t…

[github.com/openshift/osin] OpenShift OSIN vulnerable to Observable Timing Discrepancy

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/10/2023

A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch i…

[github.com/usememos/memos] usememos/memos has Insufficient Granularity of Access Control

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

An Insufficient Granularity of Access Control in usememos/memos prior to 0.9.0 can allow an attacker to delete a memo from the archives.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4813
https://github.com/usememos/memos/commit/3556ae4e651d944…

[github.com/usememos/memos] usememos/memos Improper Access Control vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

An Improper Access Control vulnerability in usememos/memos 0.9.0 and prior can result in a user deleting others’ public and private memos.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4806
https://github.com/usememos/memos/commit/3556ae4e651d9…

[github.com/usememos/memos] usememos/memos Improper Access Control vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

In usememos/memos 0.9.0 and prior, users can edit and delete all other users’ shortcuts.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4807
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/boun…

[github.com/usememos/memos] usememos/memos Improper Access Control vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

In usememos/memos 0.9.0 and prior, a user can view any content from private memos from other users via the API.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4810
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53…

[github.com/usememos/memos] usememos/memos Incorrect Use of Privileged APIs vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

In usememos/memos 0.9.0 and prior, a user can archive any private memos, delete any shortcut, and edit any shortcut from other users via API.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4805
https://github.com/usememos/memos/commit/3556ae4e65…

[github.com/usememos/memos] usememos/memos Improper Authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

In usememos/memos 0.9.0 and prior, an unauthorized user can access any private memo by URL hacking a memo on the editing screen.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4811
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a…

[github.com/usememos/memos] usememos/memos vulnerable to Comparison of Object References Instead of Object Contents

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

Comparison of Object References Instead of Object Contents in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4812
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53…

[github.com/usememos/memos] usememos/memos Improper Access Control vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

Improper Access Control in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4814
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/bounties/e65b345…

Posts navigation

Previous Posts 1 … 16 17 18 19 20 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close