πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-33124 β€Ό

aiohttp v3.8.1 was discovered to contain an invalid IPv6 URL which can lead to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-34210 β€Ό

A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34173 β€Ό

In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34187 β€Ό

Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34177 β€Ό

Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related directory, allowing attackers able to configure Pipelines to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34174 β€Ό

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32126 β€Ό

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34208 β€Ό

A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34170 β€Ό

In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Johnson Controls Acquires Tempered Networks to Bring Zero Trust Cybersecurity to Connected Buildings πŸ•΄

Johnson Controls will roll out the Tempered Networks platform across deployments of its OpenBlue AI-enabled platform.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Chinese APT Group Likely Using Ransomware Attacks as Cover for IP Theft πŸ•΄

Bronze Starlight’s use of multiple ransomware families and its victim-targeting suggest there’s more to the group’s activities than just financial gain, security vendor says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-26863 β€Ό

Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2183 β€Ό

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26862 β€Ό

Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26864 β€Ό

Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2182 β€Ό

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32987 β€Ό

Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2147 β€Ό

Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32398 β€Ό

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32392 β€Ό

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32399 β€Ό

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4

πŸ“– Read

via "National Vulnerability Database".