πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41770 β€Ό

Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42054 β€Ό

ACCEL-PPP 1.12.0 has an out-of-bounds read in triton_context_schedule if the client exits after authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42053 β€Ό

The Unicorn framework through 0.35.3 for Django allows XSS via component.name.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Apache Ranger maintainers slam unflattering cloud data security comparison with Immuta πŸ—“οΈ

Immuta defends benchmark study comparing access control policy management burdens

πŸ“– Read

via "The Daily Swig".
πŸ›  Wireshark Analyzer 3.4.9 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
πŸ—“οΈ Twitch breach leads to leak of source code and streamer earnings data πŸ—“οΈ

This is like β€˜KFC losing its secret recipe’

πŸ“– Read

via "The Daily Swig".
🦿 A unique method of securing SSH 🦿

Jack Wallen offers up a different method of securing SSH that could be rather timely in helping to lock down your Linux servers.

πŸ“– Read

via "Tech Republic".
πŸ•΄ New Regulations Are Coming β€” Get a Handle on Your App Portfolio πŸ•΄

With the realization that any app could be a gateway for a larger attack, there will be more pressure than ever on companies to fully protect their entire application landscape.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-3832 β€Ό

Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40978 β€Ό

The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20605 β€Ό

Improper Input Validation vulnerability in GOT2000 series GT21 model GT2107-WTBD all versions, GT2107-WTSD all versions, GT2104-RTBD all versions, GT2104-PMBD all versions, GT2103-PMBD all versions, GOT SIMPLE series GS21 model GS2110-WTBD all versions, GS2107-WTBD all versions, GS2110-WTBD-N all versions, GS2107-WTBD-N all versions and LE7-40GU-L all versions allows a remote unauthenticated attacker to cause DoS condition of the products by sending specially crafted packets.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20603 β€Ό

Improper Input Validation vulnerability in GOT2000 series GT21 model GT2107-WTBD all versions, GT2107-WTSD all versions, GT2104-RTBD all versions, GT2104-PMBD all versions, GT2103-PMBD all versions, GOT SIMPLE series GS21 model GS2110-WTBD all versions, GS2107-WTBD all versions, GS2110-WTBD-N all versions, GS2107-WTBD-N all versions and LE7-40GU-L all versions allows a remote unauthenticated attacker to cause DoS condition of the products by sending specially crafted packets.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41865 β€Ό

HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22958 β€Ό

A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.CVSSv2.0 AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20602 β€Ό

Improper Handling of Exceptional Conditions vulnerability in GOT2000 series GT21 model GT2107-WTBD all versions, GT2107-WTSD all versions, GT2104-RTBD all versions, GT2104-PMBD all versions, GT2103-PMBD all versions, GOT SIMPLE series GS21 model GS2110-WTBD all versions, GS2107-WTBD all versions, GS2110-WTBD-N all versions, GS2107-WTBD-N all versions and LE7-40GU-L all versions allows a remote unauthenticated attacker to cause DoS condition of the products by sending specially crafted packets.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35067 β€Ό

Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41794 β€Ό

ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character is interpreted as a length value to be used in a memcpy call. The destination buffer is only 100 bytes long on the stack. Then, 'i' gets interpreted as 105 bytes to copy from the source buffer to the destination buffer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28661 β€Ό

Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36150 β€Ό

SilverStripe Framework through 4.8.1 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20604 β€Ό

Improper Input Validation vulnerability in GOT2000 series GT21 model GT2107-WTBD all versions, GT2107-WTSD all versions, GT2104-RTBD all versions, GT2104-PMBD all versions, GT2103-PMBD all versions, GOT SIMPLE series GS21 model GS2110-WTBD all versions, GS2107-WTBD all versions, GS2110-WTBD-N all versions, GS2107-WTBD-N all versions and LE7-40GU-L all versions allows a remote unauthenticated attacker to cause DoS condition of the products by sending specially crafted packets.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33903 β€Ό

In LCOS 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices, changing the password of the root user via the CLI does not change the password of the root user for SNMPv3 access. (However, changing the password of the root user via LANconfig does change the password of the root user for SNMPv3 access.)

πŸ“– Read

via "National Vulnerability Database".