βΌ CVE-2023-5002 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. Versions of pgAdmin prior to 7.6 failed to properly control the server code executed on this API, allowing an authenticated user to run arbitrary commands on the server.π Read
via "National Vulnerability Database".
βΌ CVE-2023-41029 βΌ
π Read
via "National Vulnerability Database".
Command injection vulnerability in theΓ homemng.htm endpointΓ inΓ Juplink RX4-1500 Wifi router firmware versionsΓ V1.0.2,Γ V1.0.3,Γ V1.0.4, andΓ V1.0.5Γ allows authenticated remote attackers to execute commands as root via specially crafted HTTP requests to the vulnerable endpoint.π Read
via "National Vulnerability Database".
βΌ CVE-2023-42821 βΌ
π Read
via "National Vulnerability Database".
The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corresponds with commit `14b16010c2ee7ff33a940a541d993bd043a88940`, parsing malformed markdown input with parser that uses parser.Mmark extension could result in out-of-bounds read vulnerability. To exploit the vulnerability, parser needs to have `parser.Mmark` extension set. The panic occurs inside the `citation.go` file on the line 69 when the parser tries to access the element past its length. This can result in a denial of service. Commit `14b16010c2ee7ff33a940a541d993bd043a88940`/pseudoversion `0.0.0-20230922105210-14b16010c2ee` contains a patch for this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2023-42798 βΌ
π Read
via "National Vulnerability Database".
AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1.4.1 and below can let a release job reset the git root repository to the first commit. Version 1.5.0 has a patch for this issue. As a workaround, make sure the `PROJECT_PATH_RELEASE` (e.g. `releases/`) directory is manually and actually `git cloned` properly, making it a different git repostiory from the root git repository.π Read
via "National Vulnerability Database".
βΌ CVE-2023-42811 βΌ
π Read
via "National Vulnerability Database".
aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even if tag verification fails. If a program using the `aes-gcm` crate's `decrypt_in_place*` APIs accesses the buffer after decryption failure, it will contain a decryption of an unauthenticated input. Depending on the specific nature of the program this may enable Chosen Ciphertext Attacks (CCAs) which can cause a catastrophic breakage of the cipher including full plaintext recovery. Version 0.10.3 contains a fix for this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2023-42812 βΌ
π Read
via "National Vulnerability Database".
Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and read their responses. Version 22.05 contains a patch for this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2023-41027 βΌ
π Read
via "National Vulnerability Database".
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.π Read
via "National Vulnerability Database".
βΌ CVE-2023-41031 βΌ
π Read
via "National Vulnerability Database".
Command injection inΓ homemng.htmΓ inΓ Juplink RX4-1500 versions V1.0.2,Γ V1.0.3,Γ V1.0.4, andΓ V1.0.5Γ allows remote authenticated attackers to execute commands via specially crafted requests to the vulnerable endpoint.π Read
via "National Vulnerability Database".
βΌ CVE-2023-40989 βΌ
π Read
via "National Vulnerability Database".
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.π Read
via "National Vulnerability Database".
π¦Ώ Cisco to Acquire Splunk for $28 Billion, Accelerating AI-Enabled Security and Observability π¦Ώ
π Read
via "Tech Republic".
On Thursday Cisco agreed to buy Splunk in a $28 billion deal intended to address AI-enabled security and observability issues.π Read
via "Tech Republic".
TechRepublic
Cisco to Acquire Cybersecurity Company Splunk for $28 Billion
On Thursday Cisco agreed to buy Splunk in a $28 billion deal intended to address AI-enabled security and observability issues.
βοΈ LastPass: βHorse Gone Barn Boltedβ is Strong Password βοΈ
π Read
via "Krebs on Security".
The password manager service LastPass is now forcing some of its users to pick longer master passwords. LastPass says the changes are needed to ensure all customers are protected by their latest security improvements. But critics say the move is little more than a public relations stunt that will do nothing to help countless early adopters whose password vaults were exposed in a 2022 breach at LastPass.π Read
via "Krebs on Security".
Krebs on Security
LastPass: βHorse Gone Barn Boltedβ is Strong Password
The password manager service LastPass is now forcing some of its users to pick longer master passwords. LastPass says the changes are needed to ensure all customers are protected by their latest security improvements. But critics say the move isβ¦
βΌ CVE-2023-43130 βΌ
π Read
via "National Vulnerability Database".
D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection.π Read
via "National Vulnerability Database".
βΌ CVE-2023-43129 βΌ
π Read
via "National Vulnerability Database".
D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.π Read
via "National Vulnerability Database".
βΌ CVE-2023-5134 βΌ
π Read
via "National Vulnerability Database".
The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode in versions up to, and including, 2.1.1 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabilities or above, to retrieve arbitrary sensitive user meta.π Read
via "National Vulnerability Database".
βΌ CVE-2023-5125 βΌ
π Read
via "National Vulnerability Database".
The Contact Form by FormGet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formget' shortcode in versions up to, and including, 5.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2022-3962 βΌ
π Read
via "National Vulnerability Database".
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1625 βΌ
π Read
via "National Vulnerability Database".
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1260 βΌ
π Read
via "National Vulnerability Database".
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.π Read
via "National Vulnerability Database".
π₯1
βΌ CVE-2023-1633 βΌ
π Read
via "National Vulnerability Database".
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1636 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.π Read
via "National Vulnerability Database".
π₯2
βΌ CVE-2023-5144 βΌ
π Read
via "National Vulnerability Database".
** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected is an unknown function of the file /sysmanage/updateos.php. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240240. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.π Read
via "National Vulnerability Database".