Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[github.com/ntbosscher/gobase] GoBase Race Condition vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

A race condition can cause incorrect HTTP request routing.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2583
https://github.com/ntbosscher/gobase/commit/a8d40bce9c429d324122d18c446924dab809e812
https://pkg.go.dev/vuln/GO-2022-0400
https://gith…

[github.com/dinever/golf] Golf may allow attacker to bypass CSRF protections

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

CSRF tokens are generated using math/rand, which is not a cryptographically secure rander number generation, making predicting their values relatively trivial and allowing an attacker to bypass CSRF protections which relatively few requests.
References…

[github.com/aws/aws-sdk-go] AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SD…

[gopkg.in/yaml.v2] yaml package for Go can consume excessive amounts of CPU or memory

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3064
https://github.com/go-yaml/yaml/commit/f221b8435cfb71e54062f6c6e99e9ade30b124d5
https://github.com/go-y…

[nsupdate] nsupdate.info has Sensitive Cookie Without ‘HttpOnly’ Flag

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202201/10/2023

A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cooki…

[github.com/usememos/memos] usememos/memos may leak user information to an authenticated user

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

usememos/memos 0.9.0 and prior has endpoint that leaks user information like names, email, role, and OpenID to an authenticated user. A patch is available at commit 05b41804e33a34102f1f75bb2d69195dda6a1210 on the main branch.
References

https://nvd.ni…

[github.com/usememos/memos] usememos/memos vulnerable to stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Cross-site Scripting (XSS) – Stored in GitHub repository usememos/memos prior to 0.9.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4695
https://github.com/usememos/memos/commit/65cc19c12efa392f792f6bb154b4838547e0af5e
https://huntr.dev/bount…

[github.com/usememos/memos] usememos/memos vulnerable to stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Cross-site Scripting (XSS) – Stored in GitHub repository usememos/memos prior to 0.9.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4694
https://github.com/usememos/memos/commit/65cc19c12efa392f792f6bb154b4838547e0af5e
https://huntr.dev/bount…

[github.com/usememos/memos] usememos/memos vulnerable to stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

Cross-site Scripting (XSS) – Stored in GitHub repository usememos/memos prior to 0.9.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4691
https://github.com/usememos/memos/commit/c07b4a57caa89905e54b800f4d8fb720bbf5bf82
https://huntr.dev/bount…

[com.amazonaws:aws-android-sdk-mobile-client] AWS SDK is vulnerable to server-side request forgery (SSRF)

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/30/2022

A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-core/src/main/java/com/amazonaws/util/XpathUtils.java of the component XML Parser. The manipulation leads…

Posts navigation

Previous Posts 1 … 19 20 21 22 23 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close