🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2022-40189 ‼

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue affects Pig Provider versions prior to 4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Pig Provider is installed (Pig Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the Pig Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-40954 ‼

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files. This issue affects Spark Provider versions prior to 4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Spark Provider is installed (Spark Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the Spark Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version that has lower version of the Spark Provider installed).

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41131 ‼

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue affects Hive Provider versions prior to 4.1.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case HIve Provider is installed (Hive Provider 4.1.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the HIve Provider version 4.1.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version that has lower version of the Hive Provider installed).

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-45363 ‼

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-38649 ‼

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue affects Apache Airflow Pinot Provider versions prior to 4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Apache Airflow Pinot Provider is installed (Apache Airflow Pinot Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the Pinot Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version.

📖 Read

via "National Vulnerability Database".
🕴 CybeReady Releases Five Easy Tips to Shop Safely During Black Friday 🕴

Safe shopping guidance coupled with new CISO tool to help safeguard personal data and corporate networks.

📖 Read

via "Dark Reading".
🕴 Two Estonian Citizens Arrested in $575 Million Cryptocurrency Fraud and Money Laundering Scheme 🕴

.

📖 Read

via "Dark Reading".
🕴 FIDO Alliance Announces Authenticate Virtual Summit Focused on Securing IoT 🕴

Industry experts to share insights into how FIDO and related technologies can bring password-less authentication to IoT.

📖 Read

via "Dark Reading".
🕴 Hack The Box Launches Annual University CTF to Inspire Next Generation of Security Professionals 🕴

.

📖 Read

via "Dark Reading".
‼ CVE-2022-42097 ‼

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-44198 ‼

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42989 ‼

ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-44191 ‼

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41445 ‼

A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-44187 ‼

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42098 ‼

KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-44188 ‼

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-38462 ‼

Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-0222 ‼

A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3.40), Modicon M340 X80 Ethernet Communication modules:BMXNOE0100 (H), BMXNOE0110 (H), BMXNOR0200H RTU(BMXNOE* all versions)(BMXNOR* versions prior to v1.7 IR24)

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33012 ‼

Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-44193 ‼

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.

📖 Read

via "National Vulnerability Database".