πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-32067 β€Ό

The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system information through an HTTP response due to insufficient output sanitization.

πŸ“– Read

via "National Vulnerability Database".
❌ Exchange Servers Under Active Attack via ProxyShell Bugs ❌

There’s an entirely new attack surface in Exchange, a researcher revealed at Black Hat, and threat actors are now exploiting servers vulnerable to the RCE bugs.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-21829 β€Ό

A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T LabsÒ€ℒ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21830 β€Ό

A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T LabsÒ€ℒ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
❌ SolarWinds 2.0 Could Ignite Financial Crisis – Podcast ❌

That’s what NY State suggests could happen, given the utter lack of cybersec protection at many private equity & hedge fund firms. Can AI help avert it?

πŸ“– Read

via "Threat Post".
❌ Cyberattackers Embrace CAPTCHAs to Hide Phishing, Malware ❌

CAPTCHA-protected malicious URLs are snowballing lately, researchers said.

πŸ“– Read

via "Threat Post".
❌ Amazon’s Plan to Track Worker Keystrokes: A Sign of Controls to Come? ❌

Data theft, insider threats and imposters accessing sensitive customer data have apparently gotten so bad inside Amazon, the company is considering rolling out keyboard-stroke monitoring for its customer-service reps. A confidential memo from inside Amazon explained that customer service credential abuse and data theft was on the rise, according to Motherboard which reviewed the document. […]

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-21066 β€Ό

An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42aac.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21064 β€Ό

A buffer-overflow vulnerability in the AP4_RtpAtom::AP4_RtpAtom function in Ap4RtpAtom.cpp of Bento4 1.5.1.0 allows attackers to cause a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37705 β€Ό

OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To be vulnerable, a OneFuzz deployment must be both version 2.12.0 or greater and deployed with the non-default --multi_tenant_domain option. This can result in read/write access to private data such as software vulnerability and crash information, security testing tools and proprietary code and symbols. Via authorized API calls, this also enables tampering with existing data and unauthorized code execution on Azure compute resources. This issue is resolved starting in release 2.31.0, via the addition of application-level check of the bearer token's `issuer` against an administrator-configured allowlist. As a workaround users can restrict access to the tenant of a deployed OneFuzz instance < 2.31.0 by redeploying in the default configuration, which omits the `--multi_tenant_domain` option.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38709 β€Ό

In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26086 β€Ό

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38711 β€Ό

In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38713 β€Ό

imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38712 β€Ό

OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38708 β€Ό

In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24538 β€Ό

The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24527 β€Ό

The User Registration & User Profile ΓƒΒ’Γ’β€šΒ¬Γ’β‚¬Ε“ Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24445 β€Ό

The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24540 β€Ό

The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24536 β€Ό

The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".