πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-42078 β€Ό

PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/events_manager.php title parameter. This can be exploited by an adversary in multiple ways, e.g., to perform actions on the page in the context of other users, or to deface the site.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31600 β€Ό

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all valid usernames.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42074 β€Ό

An issue was discovered in Barrier before 2.3.4. An unauthenticated attacker can cause a segmentation fault in the barriers component (aka the server-side implementation of Barrier) by quickly opening and closing TCP connections while sending a Hello message for each TCP session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42072 β€Ό

An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided protocol to cause denial-of-service or stage further attacks that could lead to information leaks or integrity corruption.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42075 β€Ό

An issue was discovered in Barrier before 2.3.4. The barriers component (aka the server-side implementation of Barrier) does not correctly close file descriptors for established TCP connections. An unauthenticated remote attacker can thus cause file descriptor exhaustion in the server process, leading to denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42076 β€Ό

An issue was discovered in Barrier before 2.3.4. An attacker can cause memory exhaustion in the barriers component (aka the server-side implementation of Barrier) and barrierc by sending long TCP messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42370 β€Ό

A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties. (Viewing the passwords requires configuring a web browser to display HTML password input fields.)

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Interpol issues arrest warrants for members of Clop ransomware gang πŸ—“οΈ

Wanted: cybercriminals behind global malware campaign

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Campaigning lawyers launch counter-offensive against software patent trolls πŸ—“οΈ

Stemming the tide of β€˜stupid software patents and the trolls they feed’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Could Cyber Diplomacy Be the Ultimate Answer to American Ransomware Woes? πŸ•΄

Incentives for good conduct and deterrents for bad behavior in cyberspace are impossible to effectively establish and enforce without international collaboration and commitment.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-32482 β€Ό

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32483 β€Ό

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30132 β€Ό

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29243 β€Ό

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22051 β€Ό

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37850 β€Ό

ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling the protection of the ESET security product until a system reboot.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29994 β€Ό

Cloudera Hue 4.6.0 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32481 β€Ό

Cloudera Hue 4.6.0 allows XSS via the type parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Valeo Networks Acquires On Time Tech, Accelerating National Growth Strategy πŸ•΄

Through this latest acquisition, the company adds two more California locations.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Mozilla disables β€˜low usage’ encryption feature to resolve Thunderbird HTTP/2 vulnerability πŸ—“οΈ

Multiple flaws in email client resolved with security update

πŸ“– Read

via "The Daily Swig".