βΌ CVE-2022-22700 βΌ
π Read
via "National Vulnerability Database".
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists in the tenant.π Read
via "National Vulnerability Database".
π΄ Accelerated Ransomware Attacks Pressure Targeted Companies to Speed Response π΄
π Read
via "Dark Reading".
Threat actors have focused on two ends of the spectrum β quick, impactful attacks or stealthy intrusions β making strong prevention and faster response more important for enterprises.π Read
via "Dark Reading".
βΌ CVE-2022-21716 βΌ
π Read
via "National Vulnerability Database".
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22691 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23709 βΌ
π Read
via "National Vulnerability Database".
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22692 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23710 βΌ
π Read
via "National Vulnerability Database".
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victimΓ’β¬β’s browser.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38577 βΌ
π Read
via "National Vulnerability Database".
Heap Overflow in BaseBmpSupportLib.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22693 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22686 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23052 βΌ
π Read
via "National Vulnerability Database".
PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38578 βΌ
π Read
via "National Vulnerability Database".
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22943 βΌ
π Read
via "National Vulnerability Database".
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22687 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0265 βΌ
π Read
via "National Vulnerability Database".
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast prior to 5.1.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22695 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22690 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22689 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23051 βΌ
π Read
via "National Vulnerability Database".
PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22947 βΌ
π Read
via "National Vulnerability Database".
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23708 βΌ
π Read
via "National Vulnerability Database".
A flaw was discovered in Elasticsearch 7.17.0Γ’β¬β’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with Γ’β¬Ε*Γ’β¬οΏ½ index permissions access to this index.π Read
via "National Vulnerability Database".
π1