πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25328 β€Ό

The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25327 β€Ό

The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0247 β€Ό

An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24612 β€Ό

An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25326 β€Ό

fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24594 β€Ό

In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Putting the X Factor in XDR πŸ•΄

While extended detection and response (XDR) is effectively considered an upgrade from endpoint detection and response, enterprises must still begin with a strong EDR foundation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Future of Cyber Insurance πŸ•΄

Having cyber insurance is a good idea if the costs make sense β€” it could be the difference between going out of business and staying afloat. But it shouldn't be your first course of action.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25374 β€Ό

HashiCorp Terraform Enterprise before 202202-1 inserts Sensitive Information into a Log File.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Flurry Finance heist nets crypto thieves $295k πŸ—“οΈ

Theft topped out at six figures after DeFi platform blocked β€˜token balance multiplier’ exploit

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-24334 β€Ό

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24338 β€Ό

JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24340 β€Ό

In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24345 β€Ό

In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24339 β€Ό

JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24347 β€Ό

JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24327 β€Ό

In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24332 β€Ό

In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24329 β€Ό

In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24331 β€Ό

In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24346 β€Ό

In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

πŸ“– Read

via "National Vulnerability Database".