πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-34781 β€Ό

Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34778 β€Ό

Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messages provided in test results if certain job-level options are set, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or control test results.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34800 β€Ό

Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-34797 β€Ό

A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34809 β€Ό

Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34805 β€Ό

Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34811 β€Ό

A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33326 β€Ό

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The `/ajax/config_rollback/` API is affected by a command injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33087 β€Ό

A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31115 β€Ό

opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the response is of type YAML. An attacker must be in control of an opensearch server and convince the victim to connect to it in order to exploit this vulnerability. The problem has been patched in opensearch-ruby gem version 2.0.1. Users are advised to upgrade. There are no known workarounds for this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33082 β€Ό

An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33085 β€Ό

ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2274 β€Ό

The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2279 β€Ό

NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2280 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Latest web hacking tools – Q3 2022 πŸ—“οΈ

We take a look at the latest additions to security researchers’ armory

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-34894 β€Ό

In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2264 β€Ό

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Gitlab patches critical RCE bug in latest security release πŸ—“οΈ

Users are urged to update to the latest version

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-33103 β€Ό

Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33099 β€Ό

An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

πŸ“– Read

via "National Vulnerability Database".