πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-21305 β€Ό

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals the content of mutation option(:read/:write), allowing attackers to craft a string that can be executed as a Ruby code. If an application developer supplies untrusted inputs to the option, it will lead to remote code execution(RCE). This is fixed in versions 1.3.2 and 2.1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26910 β€Ό

Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21288 β€Ό

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather information about the Intranet infrastructure of the platform. This is fixed in versions 1.3.2 and 2.1.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Chemical Settings at Water Treatment Utility Get Hacked πŸ•΄

Remote access interface breached at Florida utility; attacker detected raising level of sodium hydroxide in water.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Malicious Code Injected via Google Chrome Extension Highlights App Risks πŸ•΄

An open source plug-in purportedly introduced tracking and malicious download code to infect nearly 2 million users, reports say.

πŸ“– Read

via "Dark Reading".
🦿 How to easily check if an email is legit or a scam, and protect yourself and your company 🦿

Use these practical guidelines to determine if something's a great deal or too good to be true.

πŸ“– Read

via "Tech Republic".
🦿 Top 5 reasons not to use fear to encourage security compliance 🦿

Security is important in any organization, but getting employees to follow protocol can be a challenge. Tom Merritt offers five reasons why using fear-based motivation techniques is not ideal.

πŸ“– Read

via "Tech Republic".
🦿 Why you shouldn't use fear to encourage security compliance: 5 reasons 🦿

Security is important in any organization, but getting employees to follow protocol can be a challenge. Tom Merritt offers five reasons why using fear-based motivation techniques is not ideal.

πŸ“– Read

via "Tech Republic".
🦿 Can your organization obtain reasonable cybersecurity? Yes, and here's how 🦿

Cybersecurity expectations are vague, and that has to change if there is any chance of approaching a reasonable amount of cybersecurity.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-22502 β€Ό

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26916 β€Ό

In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36148 β€Ό

Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-8578 β€Ό

Clustered Data ONTAP versions prior to 9.3P20 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the Γ’β‚¬β€œremove-private-data parameter is set to true.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26220 β€Ό

The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26528 β€Ό

The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after exhausting memory pool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13947 β€Ό

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25913 β€Ό

Prototype pollution vulnerability in Ò€˜set-or-getÒ€ℒ version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26530 β€Ό

The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26576 β€Ό

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26222 β€Ό

The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26529 β€Ό

The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.

πŸ“– Read

via "National Vulnerability Database".