πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ β€˜Long Live Log4Shell’: CVE-2021-44228 Not Dead Yet ❌

The ubiquitous Log4j bug will be with us for years. John Hammond, senior security researcher at Huntress, discusses what's next.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-43635 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24260 β€Ό

A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24259 β€Ό

An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24262 β€Ό

The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 2/4 πŸ”

Hacking North Korea, inside the Trickbot ransomware group, and more - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".
πŸ•΄ Expert Insights: Training the Data Elephant in the AI Room πŸ•΄

Be aware of the risk of inadvertent data exposure in machine learning systems.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-29394 β€Ό

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24249 β€Ό

A Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtra_box_write function in /box_code_base.c, which causes a Denial of Service. This vulnerability was fixed in commit 71f9871.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29397 β€Ό

Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23470 β€Ό

This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-PUTILMERGE-1317077

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29395 β€Ό

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24129 β€Ό

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23507 β€Ό

The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-OBJECTPATHSET-607908

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29398 β€Ό

Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45408 β€Ό

Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29393 β€Ό

Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23497 β€Ό

This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45429 β€Ό

A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set_configuration in yara/libyara/libyara.c, which could cause a Denial of Service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24448 β€Ό

An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29396 β€Ό

Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.

πŸ“– Read

via "National Vulnerability Database".