π¨ CVE-2022-21704
log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.
π@cveNotify
log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.
π@cveNotify
GitHub
log4js-node/CHANGELOG.md at v6.4.0 Β· log4js-node/log4js-node
A port of log4js to node.js. Contribute to log4js-node/log4js-node development by creating an account on GitHub.
π¨ CVE-2021-4143
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
π@cveNotify
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
π@cveNotify
GitHub
build: use official ep_cursortrace Β· bigbluebutton/bigbluebutton@62040bd
Complete open source web conferencing system. Contribute to bigbluebutton/bigbluebutton development by creating an account on GitHub.
π¨ CVE-2021-43269
In Code42 app before 8.8.0, eval injection allows an attacker to change a deviceβs proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)
π@cveNotify
In Code42 app before 8.8.0, eval injection allows an attacker to change a deviceβs proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)
π@cveNotify
π¨ CVE-2021-4183
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
π@cveNotify
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
π@cveNotify
GitLab
2021/CVE-2021-4183.json Β· master Β· GitLab.org / cves
This project hosts the CVEs that have been assigned by GitLab in its role as a CNA. See https://about.gitlab.com/security/cve/ for more information
π¨ CVE-2021-4182
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
π¨ CVE-2021-4186
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
GitLab
2021/CVE-2021-4186.json Β· master Β· GitLab.org / cves
This project hosts the CVEs that have been assigned by GitLab in its role as a CNA. See https://about.gitlab.com/security/cve/ for more information
π¨ CVE-2021-4184
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
π¨ CVE-2021-4190
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
π@cveNotify
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
π@cveNotify
GitLab
2021/CVE-2021-4190.json Β· master Β· GitLab.org / GitLab CVE assignments Β· GitLab
This project hosts the CVEs that have been assigned by GitLab in its role as a CNA. See https://about.gitlab.com/security/cve/ for more information
π¨ CVE-2021-4185
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
π¨ CVE-2021-4181
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
π@cveNotify
GitLab
2021/CVE-2021-4181.json Β· master Β· GitLab.org / cves Β· GitLab
This project hosts the CVEs that have been assigned by GitLab in its role as a CNA. See https://about.gitlab.com/security/cve/ for more information
π¨ CVE-2022-0278
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
π@cveNotify
GitHub
xss on contact form fix Β· microweber/microweber@b64ef57
Drag and Drop Website Builder and CMS with E-commerce - xss on contact form fix Β· microweber/microweber@b64ef57
π¨ CVE-2022-0277
Improper Access Control in Packagist microweber/microweber prior to 1.2.11.
π@cveNotify
Improper Access Control in Packagist microweber/microweber prior to 1.2.11.
π@cveNotify
GitHub
search_authors only admins Β· microweber/microweber@e680e13
Drag and Drop Website Builder and CMS with E-commerce - search_authors only admins Β· microweber/microweber@e680e13
π¨ CVE-2021-0004
Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.
π@cveNotify
Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.
π@cveNotify
Intel
INTEL-SA-00479
π¨ CVE-2022-23094
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
π@cveNotify
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
π@cveNotify
GitHub
xfrm interface ipsec1 exist after core dump and blocking restart of ipsec service clean Β· Issue #585 Β· libreswan/libreswan
After setting up plutodebug=base, I got the packet which may cause core dump when ikev1 is not accept Dec 21 02:43:35 localhost pluto[2787]: | *received 204 bytes from 101.4.62.36:43357 on eth0 192...
π¨ CVE-2022-22733
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.
π@cveNotify
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.
π@cveNotify
π¨ CVE-2022-0281
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
π@cveNotify
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
π@cveNotify
GitHub
search_authors only admins Β· microweber/microweber@e680e13
Drag and Drop Website Builder and CMS with E-commerce - search_authors only admins Β· microweber/microweber@e680e13
π¨ CVE-2022-0281
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
π@cveNotify
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
π@cveNotify
GitHub
search_authors only admins Β· microweber/microweber@e680e13
Drag and Drop Website Builder and CMS with E-commerce - search_authors only admins Β· microweber/microweber@e680e13
π¨ CVE-2021-45230
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
π@cveNotify
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
π@cveNotify
π¨ CVE-2021-45230
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
π@cveNotify
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.
π@cveNotify
π¨ CVE-2021-3866
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip prior to main.
π@cveNotify
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip prior to main.
π@cveNotify
huntr.dev
Cross-site Scripting (XSS) - Stored in zulip
14.81K developers have been protected by securing zulip. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
π¨ CVE-2021-3866
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip prior to main.
π@cveNotify
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip prior to main.
π@cveNotify
huntr.dev
Cross-site Scripting (XSS) - Stored in zulip
14.81K developers have been protected by securing zulip. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.