Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[github.com/revel/revel] revel is vulnerable to resource exhaustion

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/30/2022

Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36568
https://github.com/revel/revel/issues/…

[github.com/yi-ge/unzip] Unzip vulnerable to path traversal

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36561
https://github.com/yi-ge/unzip/pull/1
…

[github.com/go-aah/aah] ahh vulnerable to Path Traversal

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Due to improper santization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
References

https://nvd.nist.gov/vuln/detail/CVE-202…

[github.com/cloudfoundry/archiver] Cloud Foundry Archiver vulnerable to path traversal

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-25046
https://github.com/cloudfoundry/archiv…

[github.com/gorilla/handlers] gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.
References

https://nvd.nist.go…

[github.com/robbert229/jwt] robbert229/jwt’s token validation methods vulnerable to a timing side-channel during HMAC comparison

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.
References

https://nvd.nist.gov/vu…

[github.com/justinas/nosurf] nosurf vulnerable to improper input validation

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36564
https://github….

[github.com/Masterminds/goutils] GoUtils’s randomly-generated alphanumeric strings contain significantly less entropy than expected

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amou…

[github.com/artdarek/go-unzip] go-unzip vulnerable to Path Traversal

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36560
https://github.com/artdarek/go-unzip/p…

[goa.design/goa/v3] Goa vulnerable to path traversal

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202201/07/2023

Improper path santiziation in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-25073
https://github.com/goadesign/go…

Posts navigation

Previous Posts 1 … 18 19 20 21 22 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close