π¨ CVE-2020-13931
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.
π@cveNotify
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.
π@cveNotify
π¨ CVE-2020-28460
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.
π@cveNotify
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.
π@cveNotify
GitHub
Fixed 2nd issue with prototype pollution Β· evangelion1204/multi-ini@6b2212b
Read multilevel and multiline ini files in compatible with Zend. - evangelion1204/multi-ini
π¨ CVE-2020-28448
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
π@cveNotify
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
π@cveNotify
GitHub
Fix prototype pollution by evangelion1204 Β· Pull Request #37 Β· evangelion1204/multi-ini
Fixed prototype pollution by ignoring __proto__ in sections and keys.
Steps to reproduce
payload.ini
[__proto__]
polluted = "polluted"
poc.js:
var ini = require('multi-ini...
Steps to reproduce
payload.ini
[__proto__]
polluted = "polluted"
poc.js:
var ini = require('multi-ini...
π¨ CVE-2020-29564
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
π@cveNotify
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
π@cveNotify
GitHub
CVE/CVE-2020-29564 at main Β· koharin/CVE
Contribute to koharin/CVE development by creating an account on GitHub.
π¨ CVE-2020-29575
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
π@cveNotify
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
π@cveNotify
π¨ CVE-2020-29576
The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
π@cveNotify
The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
π@cveNotify
GitHub
CVE/CVE-2020-29576 at main Β· koharin/CVE
Contribute to koharin/CVE development by creating an account on GitHub.
π¨ CVE-2020-26198
Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victimβs browser by tricking a victim in to following a specially crafted link.
π@cveNotify
Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victimβs browser by tricking a victim in to following a specially crafted link.
π@cveNotify
Dell
DSA-2020-268: Dell EMC iDRAC9 Reflected XSS Vulnerability | Dell UK
Dell EMC iDRAC has been updated to address a vulnerability that may be exploited to compromise the affected systems.
π¨ CVE-2020-29577
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
π@cveNotify
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
π@cveNotify
π¨ CVE-2020-29578
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
π@cveNotify
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
π@cveNotify
π¨ CVE-2020-17520
In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.
π@cveNotify
In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.
π@cveNotify
π¨ CVE-2019-11781
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
π@cveNotify
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
π@cveNotify
GitHub
[SEC] CVE-2019-11781 - Affects: Odoo 12.0 and earlier (Community an... Β· Issue #63706 Β· odoo/odoo
Security Advisory - CVE-2019-11781 Affects: Odoo 12.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11781 Component: Portal Credits: "iamsushi" Improper input v...
π¨ CVE-2019-11784
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.
π@cveNotify
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.
π@cveNotify
GitHub
[SEC] CVE-2019-11784 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63709 Β· odoo/odoo
Security Advisory - CVE-2019-11784 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11784 Component: Discuss Improper access control in mail module (notifications...
π¨ CVE-2019-11786
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.
π@cveNotify
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.
π@cveNotify
GitHub
[SEC] CVE-2019-11786 - Affects: Odoo 13.0 and earlier (Community an... Β· Issue #63711 Β· odoo/odoo
Security Advisory - CVE-2019-11786 Affects: Odoo 13.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11786 Component: Core Credits: Martin Trigaux, Alexandre Diaz Improper access ...
π¨ CVE-2018-15632
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.
π@cveNotify
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.
π@cveNotify
GitHub
[SEC] CVE-2018-15632 - Affects: Odoo 11.0 and earlier (Community an... Β· Issue #63700 Β· odoo/odoo
Security Advisory - CVE-2018-15632 Affects: Odoo 11.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15632 Component: Framework Credits: P. Valov (SoCyber) Improper input validati...
π¨ CVE-2018-15633
Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.
π@cveNotify
Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.
π@cveNotify
GitHub
[SEC] CVE-2018-15633 - Affects: Odoo 11.0 and earlier (Community an... Β· Issue #63701 Β· odoo/odoo
Security Advisory - CVE-2018-15633 Affects: Odoo 11.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15633 Component: "document" module Credits: Nathanael ROTA (...
π¨ CVE-2018-15634
Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.
π@cveNotify
Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.
π@cveNotify
GitHub
[SEC] CVE-2018-15634 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63702 Β· odoo/odoo
Security Advisory - CVE-2018-15634 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15634 Component: Framework Credits: Nathanael ROTA (Capgemini) and Alessandro ...
π¨ CVE-2018-15638
Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.
π@cveNotify
Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.
π@cveNotify
GitHub
[SEC] CVE-2018-15638 - Affects: Odoo 13.0 and earlier (Community an... Β· Issue #63703 Β· odoo/odoo
Security Advisory - CVE-2018-15638 Affects: Odoo 13.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15638 Component: Discuss Credits: Subash SN and Bharath Kumar (Appsecco), Dipa...
π¨ CVE-2018-15641
Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
π@cveNotify
Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
π@cveNotify
GitHub
[SEC] CVE-2018-15641 - Affects: Odoo 11.0 through 14.0 (Community a... Β· Issue #63704 Β· odoo/odoo
Security Advisory - CVE-2018-15641 Affects: Odoo 11.0 through 14.0 (Community and Enterprise Editions) CVE ID: CVE-2018-15641 Component: Framework Credits: msg systems ag, Lauri Vakkala (Silverskin...
π¨ CVE-2019-11782
Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.
π@cveNotify
Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.
π@cveNotify
GitHub
[SEC] CVE-2019-11782 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63707 Β· odoo/odoo
Security Advisory - CVE-2019-11782 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11782 Component: Portal Credits: Damien LESCOS Improper access control in Odoo...
π¨ CVE-2018-15645
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
π@cveNotify
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
π@cveNotify
GitHub
[SEC] CVE-2018-15645 - Affects: Odoo 12.0 and earlier (Community an... Β· Issue #63705 Β· odoo/odoo
Security Advisory - CVE-2018-15645 Affects: Odoo 12.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15645 Component: Discuss Credits: Nils Hamerlinck (Trobz) Improper access cont...
π¨ CVE-2019-11783
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
π@cveNotify
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
π@cveNotify
GitHub
[SEC] CVE-2019-11783 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63708 Β· odoo/odoo
Security Advisory - CVE-2019-11783 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11783 Component: Discuss Credits: Nils Hamerlinck (Trobz), Christopher Riis Bu...