πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38136 β€Ό

Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A Γ’β‚¬Λœlow privilegedÒ€ℒ attacker can read any file on the target host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37547 β€Ό

In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37550 β€Ό

In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37551 β€Ό

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37553 β€Ό

In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37542 β€Ό

In JetBrains TeamCity before 2020.2.3, XSS was possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37540 β€Ό

In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37554 β€Ό

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37549 β€Ό

In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36708 β€Ό

In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37544 β€Ό

In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26998 β€Ό

NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36209 β€Ό

In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36706 β€Ό

In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37546 β€Ό

In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37543 β€Ό

In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.

πŸ“– Read

via "National Vulnerability Database".
❌ Amazon Kindle Vulnerable to Malicious EBooks ❌

Prior to a patch, a serious bug could have allowed attackers to take over Kindles and steal personal data.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-35312 β€Ό

A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18693 β€Ό

Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18694 β€Ό

Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/admin/profile/save_profile".

πŸ“– Read

via "National Vulnerability Database".
❌ Golang Cryptomining Worm Offers 15% Speed Boost ❌

The latest variants of the Monero-mining malware exploit known web server bugs and add efficiency to the mining process.

πŸ“– Read

via "Threat Post".