🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2020-28481 ‼

The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-28482 ‼

This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts: { path: '/', sameSite: true } 2. The CSRF token was available in the GET query parameter

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-3182 ‼

** UNSUPPORTED WHEN ASSIGNED ** D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-27733 ‼

Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-3184 ‼

MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-4871 ‼

IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-25325 ‼

MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-28480 ‼

The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype Pollution.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-4881 ‼

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 190851.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-4873 ‼

IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-3181 ‼

rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-3183 ‼

Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-25323 ‼

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-25324 ‼

MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-22498 ‼

XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited to allow an XML External Entity Injection.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-28479 ‼

The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.

📖 Read

via "National Vulnerability Database".
🕴 The Most Pressing Concerns Facing CISOs Today 🕴

Building security into the software development life cycle creates more visibility, but CISOs still need stay on top of any serious threats on the horizon, even if they are largely unknown.

📖 Read

via "Dark Reading".
🦿 CES 2021: All of the business tech news you need to know 🦿

Don't miss TechRepublic's CES 2021 coverage, which includes product announcements from Lenovo, Samsung, LG, and Dell about PCs, laptops, software, robots, monitors, and TVs.

📖 Read

via "Tech Republic".
🦿 How to enable enhanced randomize MAC addresses on Android 🦿

Android 11 allows users to enable the Wi-Fi-Enhanced MAC randomization. Jack Wallen shows you how.

📖 Read

via "Tech Republic".
🦿 Politics and online privacy: How American Republicans and Democrats differ, and where they agree 🦿

A report from NordVPN finds disagreement on which political leader does better on privacy issues, whether disinformation should be banned, and what the biggest cyberthreat is.

📖 Read

via "Tech Republic".
🦿 CES 2021: All of the business tech news you need to know 🦿

Don't miss TechRepublic's CES 2021 coverage, which includes product announcements from Lenovo, Samsung, LG, and Dell about PCs, laptops, software, robots, monitors, and TVs.

📖 Read

via "Tech Republic".