❌ Jenkins Hit as Atlassian Confluence Cyberattacks Widen ❌
📖 Read
via "Threat Post".
Patch now: The popular biz-collaboration platform is seeing mass scanning and exploitation just two weeks after a critical RCE bug was disclosed.📖 Read
via "Threat Post".
Threat Post
Jenkins Hit as Atlassian Confluence Cyberattacks Widen
Patch now: The popular biz-collaboration platform is seeing mass scanning and exploitation just two weeks after a critical RCE bug was disclosed.
🦿 How to control activity tracking by apps on your iPhone or iPad 🦿
📖 Read
via "Tech Republic".
You can tell iOS and iPadOS apps not to track your activity. Here's how.📖 Read
via "Tech Republic".
TechRepublic
How to control activity tracking by apps on your iPhone or iPad
You can tell iOS and iPadOS apps not to track your activity. Here's how.
‼ CVE-2021-40539 ‼
📖 Read
via "National Vulnerability Database".
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38123 ‼
📖 Read
via "National Vulnerability Database".
Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39197 ‼
📖 Read
via "National Vulnerability Database".
better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It is also usable outside of Rails in any Rack app as Rack middleware. better_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the `development` bundle group, so this vulnerability should only affect development environments. Please ensure that your project limits better_errors to the `development` group (or the non-Rails equivalent). Starting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". There are no known workarounds to mitigate the risk of using older releases of better_errors.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38142 ‼
📖 Read
via "National Vulnerability Database".
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows Sender due to the fact that the upgrade mechanism is not secured (is not protected with TLS).📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39195 ‼
📖 Read
via "National Vulnerability Database".
Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information within the internal network. This has been fixed in 12.90.0. However, if you are using a proxy, you will need to take additional measures. As a workaround this exploit may be avoided by appropriately restricting access to private networks from the host where the application is running.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-35947 ‼
📖 Read
via "National Vulnerability Database".
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39196 ‼
📖 Read
via "National Vulnerability Database".
pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter and without adequate permissions. This is important because the capture filters can effectively limit the scope of information that a user can see in the data captures. If no filter is present, then all data on the local network segment where the program is running can be captured and downloaded. v3.12 fixes this problem. There is no workaround, you must upgrade to v3.12 or greater.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39199 ‼
📖 Read
via "National Vulnerability Database".
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and had to be opted into. That is, user input was not sanitized. This means arbitrary HTML can be passed through leading to potential XSS attacks. The problem has been patched in 13.0.2 and 14.0.1: `remark-html` is now safe by default, and the implementation matches the documentation. On older affected versions, pass `sanitize: true` if you cannot update.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-35949 ‼
📖 Read
via "National Vulnerability Database".
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.📖 Read
via "National Vulnerability Database".
❌ Netgear Smart Switches Open to Complete Takeover ❌
📖 Read
via "Threat Post".
The Demon's Cries, Draconian Fear and Seventh Inferno security bugs are high-severity entryways to corporate networks.📖 Read
via "Threat Post".
Threat Post
Netgear Smart Switches Open to Complete Takeover
The Demon's Cries, Draconian Fear and Seventh Inferno security bugs are high-severity entryways to corporate networks.
‼ CVE-2021-37629 ‼
📖 Read
via "National Vulnerability Database".
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. It is recommended that the Nextcloud Richdocuments app is upgraded to either 3.8.4 or 4.2.1 to resolve. For users unable to upgrade it is recommended that the Richdocuments application be disabled.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39499 ‼
📖 Read
via "National Vulnerability Database".
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39496 ‼
📖 Read
via "National Vulnerability Database".
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-35946 ‼
📖 Read
via "National Vulnerability Database".
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32766 ‼
📖 Read
via "National Vulnerability Database".
Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder existed in a public link share. This is problematic in case the public link share has been created with "Upload Only" privileges. (aka "File Drop"). A link share recipient is not expected to see which folders or files exist in a "File Drop" share. Using this vulnerability an attacker is able to enumerate folders in such a share. Exploitation requires that the attacker has access to a valid affected "File Drop" link share. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.0.1. Users who are unable to upgrade are advised to disable the Nextcloud Text application in the app settings.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-19752 ‼
📖 Read
via "National Vulnerability Database".
The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38706 ‼
📖 Read
via "National Vulnerability Database".
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38707 ‼
📖 Read
via "National Vulnerability Database".
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39503 ‼
📖 Read
via "National Vulnerability Database".
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.📖 Read
via "National Vulnerability Database".