πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-23060 β€Ό

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the Ò€œManage filesҀ� tab

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1544 β€Ό

Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23061 β€Ό

In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31674 β€Ό

Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28451 β€Ό

nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40822 β€Ό

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29849 β€Ό

In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escalation. If exploited, a local attacker could elevate their privileges and compromise the affected system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29968 β€Ό

An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31673 β€Ό

A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Deep Dive: Protecting Against Container Threats in the Cloud ❌

A deep dive into securing containerized environments and understanding how they present unique security challenges.

πŸ“– Read

via "Threat Post".
πŸ‘1
πŸ—“οΈ Security bug in VMWare Workspace ONE could allow access to internal, cloud networks πŸ—“οΈ

Users should patch immediately

πŸ“– Read

via "The Daily Swig".
❌ Bad Actors Are Maximizing Remote Everything ❌

Aamir Lakhani, global security strategist and researcher at FortiGuard Labs, zeroes in on how adversaries are targeting 'remote everything'.

πŸ“– Read

via "Threat Post".
πŸ•΄ Security Stuff Happens: What Do You Do When It Hits the Fan? πŸ•΄

Breaches can happen to anyone, but a well-oiled machine can internally manage and externally remediate in a way that won't lead to extensive damage to a company's bottom line. (Part 1 of a series.)

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-36784 β€Ό

A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29973 β€Ό

relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in certain situations involving offsets beyond ValidDataLength.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28572 β€Ό

Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36778 β€Ό

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23064 β€Ό

In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46790 β€Ό

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4200 β€Ό

A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23065 β€Ό

In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the Ò€œAssetsҀ� tab. The uploaded file will affect administrators as well as regular users.

πŸ“– Read

via "National Vulnerability Database".