πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-46288 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0.Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_configΓ‚ option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_configΓ‚ to non-sensitive-onlyΓ‚ configuration. This is a different error than CVE-2023-45348Γ‚ which allows authenticated user to retrieve individual configuration values in 2.7.* by specially crafting their request (solved in 2.7.2).Users are recommended to upgrade to version 2.7.2, which fixes the issue and additionally fixesΓ‚ CVE-2023-45348.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38722 β€Ό

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262174.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43045 β€Ό

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Valve's 2FA Mandate for Game Developers Shows SMS Stickiness πŸ•΄

Despite warnings that sending one-time passwords via text messages is a flawed security measure, companies continue to roll out the approach, especially in consumer-facing applications.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cyberattackers Alter Implant on 30K Compromised Cisco IOS XE Devices πŸ•΄

A seemingly sharp drop in the number of compromised Cisco IOS XE devices visible on the Internet led to a flurry of speculation over the weekend β€” but it turns out the malicious implants were just hiding.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-27152 β€Ό

DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27149 β€Ό

A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22466 β€Ό

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 225222.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37636 β€Ό

A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33839 β€Ό

IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 256036.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46602 β€Ό

In International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in IccXML/IccLibXML/IccUtilXml.cpp in libIccXML.a.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33840 β€Ό

IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256037.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46603 β€Ό

In International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function in IccProfLib/IccPrmg.cpp in libSampleICC.a.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37635 β€Ό

UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33837 β€Ό

IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45966 β€Ό

umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27148 β€Ό

A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯2
β€Ό CVE-2023-46058 β€Ό

Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the grp_desc parameter of the admin/group.php component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46059 β€Ό

Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the Service, and website URL to Ping parameters of the admin/trackback.php component.

πŸ“– Read

via "National Vulnerability Database".
🦿 Generative AI Can Write Phishing Emails, But Humans Are Better At It, IBM X-Force Finds 🦿

Hacker Stephanie "Snow" Carruthers and her team found phishing emails written by security researchers saw a 3% better click rate than phishing emails written by ChatGPT.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 'Log in with...' Feature Allows Full Online Account Takeover for Millions πŸ•΄

Hundreds of millions of users of Grammarly, Vidio, and the Indonesian e-commerce giant Bukalapak are at risk for financial fraud and credential theft due to OAuth misfires -- and other online services likely have the same problems.

πŸ“– Read

via "Dark Reading".