#漏洞 【漏洞分析】CVE-2021-29200 Apache OFBiz RMI Bypass RCE 分析
https://mp.weixin.qq.com/s/vM0pXZ5mhusFBsj1xD-2zw
https://mp.weixin.qq.com/s/vM0pXZ5mhusFBsj1xD-2zw
Weixin Official Accounts Platform
【漏洞分析】CVE-2021-29200 Apache OFBiz RMI Bypass RCE 分析
CVE-2021-29200 Apache OFBiz RMI Bypass RCE ,通过黑名单绕过,从而造成一个反序列化远程命令执行漏洞
#漏洞 Open Distro for Elasticsearch SSRF漏洞(CVE-2021-31828)
https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828?guid=none&deviceId=8277082d-b611-40d0-9c28-e15797f0ab39
https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828?guid=none&deviceId=8277082d-b611-40d0-9c28-e15797f0ab39
My Publications
CVE-2021-31828 - SSRF in Open Distro for ElasticSearch
#漏洞 CVE‑2021‑1079 – NVIDIA GeForce Experience命令执行
https://voidsec.com/nvidia-geforce-experience-command-execution/
https://voidsec.com/nvidia-geforce-experience-command-execution/
VoidSec
CVE‑2021‑1079 - NVIDIA GeForce Experience Command Execution - VoidSec
CVE-2021-1079: NVIDIA GeForce Experience (GFE) v.<= 3.21 is affected by an Arbitrary File Write vulnerability which lead to Command Execution.
#漏洞 Cisco RV34X系列 权限提升漏洞(CVE-2021-1520)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
ONEKEY
Advisory: Cisco RV34X Series - Privilege Escalation in vpnTimer - ONEKEY
IoT Inspector detected a rare security vulnerability in Cisco's RV34X Series. Read the full root analysis on the blog!
#漏洞 前端JS框架Aurelia不安全默认值可导致XSS
https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/
https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/
GoSecure
24/7 managed detection, response, and expert cybersecurity services - GoSecure
We provide around-the-clock threat detection and incident response, backed by expert consulting to keep your organization secure.
#漏洞 NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket
https://blog.sonarsource.com/nosql-injections-in-rocket-chat/
https://blog.sonarsource.com/nosql-injections-in-rocket-chat/
Sonarsource
NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket
We recently discovered vulnerabilities in Rocket.Chat, a popular team communications solution, that could be used to take over Rock.Chat instances.
#漏洞 (u)rxvt terminal (+bash) remoteish code execution 0day
https://seclists.org/fulldisclosure/2021/May/33
https://seclists.org/fulldisclosure/2021/May/33
seclists.org
Full Disclosure: (u)rxvt terminal (+bash) remoteish code execution 0day