#漏洞 Cisco RV34X系列–身份验证绕过和远程命令执行(CVE-2021-1472/CVE-2021-1473)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/
#漏洞 Allow arbitrary URLs, expect arbitrary code execution
https://positive.security/blog/url-open-rce
https://positive.security/blog/url-open-rce
positive.security
Allow arbitrary URLs, expect arbitrary code execution | Positive Security
Insecure URL handling leading to 1-click code execution vulnerabilities in Telegram, Nextcloud (CVE-2021-22879), VLC, LibreOffice (CVE-2021-25631), OpenOffice (CVE-2021-30245), Bitcoin/Dogecoin Wallets, Wireshark (CVE-2021-22191) and Mumble (CVE-2021-27229).
#漏洞 WordPress 5.6-5.7 - Authenticated XXE (CVE-2021-29447)
https://github.com/motikan2010/CVE-2021-29447
https://github.com/motikan2010/CVE-2021-29447
GitHub
GitHub - motikan2010/CVE-2021-29447: WordPress - Authenticated XXE (CVE-2021-29447)
WordPress - Authenticated XXE (CVE-2021-29447). Contribute to motikan2010/CVE-2021-29447 development by creating an account on GitHub.
#漏洞 RCE via unsafe inline Kramdown options when rendering certain Wiki pages
https://hackerone.com/reports/1125425
https://hackerone.com/reports/1125425
HackerOne
GitLab disclosed on HackerOne: RCE via unsafe inline Kramdown...
### Summary
When rendering wiki content with certain extensions such as `.rmd`, `render_wiki_content` will call...
When rendering wiki content with certain extensions such as `.rmd`, `render_wiki_content` will call...
#漏洞 cisco RV34X系列身份绕过和远程命令执行漏洞(CVE-2021-1472 CVE-2021-1473)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/
#漏洞 Remote code execution in Homebrew by compromising the official Cask repository
https://blog.ryotak.me/post/homebrew-security-incident-en/
https://blog.ryotak.me/post/homebrew-security-incident-en/
blog.ryotak.net
Remote code execution in Homebrew by compromising the official Cask repository
この記事は日本語でも投稿されています: https://blog.ryotak.net/post/homebrew-security-incident/
(もし日本語が読める場合、筆者は英語がそこまで得意ではないため、日本語の記事を読むことをお勧めします。)
(Official blog post about this incident is available here: https://brew.sh/2021/04/21/security-incident-disclosure/)
Preface…
(もし日本語が読める場合、筆者は英語がそこまで得意ではないため、日本語の記事を読むことをお勧めします。)
(Official blog post about this incident is available here: https://brew.sh/2021/04/21/security-incident-disclosure/)
Preface…
#漏洞 Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass
https://github.com/darryk10/CVE-2021-25735
https://github.com/darryk10/CVE-2021-25735
GitHub
GitHub - darryk10/CVE-2021-25735: Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass
Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass - darryk10/CVE-2021-25735