π¨ CVE-2024-30684
An insecure logging vulnerability has been identified within ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to access sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.
π@cveNotify
An insecure logging vulnerability has been identified within ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to access sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30684: Insecure Logging Vulnerability in ROS2 Iron Irwini
Insecure Logging Vulnerability in ROS2 Iron Irwini - yashpatelphd/CVE-2024-30684
π¨ CVE-2024-30686
An issue was discovered in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code via packages or nodes within the ROS2 system.
π@cveNotify
An issue was discovered in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code via packages or nodes within the ROS2 system.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30686: Remote Command Execution Vulnerability in ROS2 Iron Irwini
Remote Command Execution Vulnerability in ROS2 Iron Irwini - yashpatelphd/CVE-2024-30686
π¨ CVE-2024-30687
An insecure deserialization vulnerability has been identified in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code via a crafted input to the Data Serialization and Deserialization Components, Inter-Process Communication Mechanisms, and Network Communication Interfaces.
π@cveNotify
An insecure deserialization vulnerability has been identified in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code via a crafted input to the Data Serialization and Deserialization Components, Inter-Process Communication Mechanisms, and Network Communication Interfaces.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30687: Insecure Deserialization Vulnerability in ROS2 Iron Irwini
Insecure Deserialization Vulnerability in ROS2 Iron Irwini - yashpatelphd/CVE-2024-30687
π¨ CVE-2024-30688
An arbitrary file upload vulnerability has been discovered in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code via a crafted payload to the file upload mechanism of the ROS2 system, including the serverβs functionality for handling file uploads and the associated validation processes.
π@cveNotify
An arbitrary file upload vulnerability has been discovered in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code via a crafted payload to the file upload mechanism of the ROS2 system, including the serverβs functionality for handling file uploads and the associated validation processes.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30688
Contribute to yashpatelphd/CVE-2024-30688 development by creating an account on GitHub.
π¨ CVE-2023-52425
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
π@cveNotify
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
π@cveNotify
GitHub
[CVE-2023-52425] Speed up parsing of big tokens by Snild-Sony Β· Pull Request #789 Β· libexpat/libexpat
When parsing a really big token that requires multiple buffer fills to complete, expat has to re-parse the token from start multiple times, which takes time. These patches introduce a heuristic tha...
π¨ CVE-2024-30690
An unauthorized node injection vulnerability has been identified in ROS2 Galactic Geochelone versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3, allows remote attackers to escalate privileges.
π@cveNotify
An unauthorized node injection vulnerability has been identified in ROS2 Galactic Geochelone versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3, allows remote attackers to escalate privileges.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30690: Unauthorized Node Injection Vulnerability in ROS2 Galactic Geochelone
Unauthorized Node Injection Vulnerability in ROS2 Galactic Geochelone - yashpatelphd/CVE-2024-30690
π¨ CVE-2024-1233
A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.
π@cveNotify
A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.
π@cveNotify
π¨ CVE-2024-30691
An issue was discovered in ROS2 Galactic Geochelone in version ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, obtain sensitive information, and gain unauthorized access to multiple ROS2 nodes.
π@cveNotify
An issue was discovered in ROS2 Galactic Geochelone in version ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, obtain sensitive information, and gain unauthorized access to multiple ROS2 nodes.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30691: Unauthorized Access Vulnerability in ROS2 Galactic Geochelone
Unauthorized Access Vulnerability in ROS2 Galactic Geochelone - yashpatelphd/CVE-2024-30691
π¨ CVE-2024-30692
A issue was discovered in ROS2 Galactic Geochelone versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to cause a denial of service (DoS) in the ROS2 nodes.
π@cveNotify
A issue was discovered in ROS2 Galactic Geochelone versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to cause a denial of service (DoS) in the ROS2 nodes.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30692: Denial-of-Service (DoS) Vulnerability in ROS2 Galactic Geochelone
Denial-of-Service (DoS) Vulnerability in ROS2 Galactic Geochelone - yashpatelphd/CVE-2024-30692
π¨ CVE-2024-30694
A shell injection vulnerability was discovered in ROS2 (Robot Operating System 2) Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, escalate privileges, and obtain sensitive information due to the way ROS2 handles shell command execution in components like command interpreters or interfaces that process external inputs.
π@cveNotify
A shell injection vulnerability was discovered in ROS2 (Robot Operating System 2) Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, escalate privileges, and obtain sensitive information due to the way ROS2 handles shell command execution in components like command interpreters or interfaces that process external inputs.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30691: Unauthorized Access Vulnerability in ROS2 Galactic Geochelone
Unauthorized Access Vulnerability in ROS2 Galactic Geochelone - yashpatelphd/CVE-2024-30691
π¨ CVE-2024-30695
An issue was discovered in the default configurations of ROS2 Galactic Geochelone versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to gain access using default credentials.
π@cveNotify
An issue was discovered in the default configurations of ROS2 Galactic Geochelone versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to gain access using default credentials.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30695: Security Misconfiguration in ROS2 Galactic Geochelone
Security Misconfiguration in ROS2 Galactic Geochelone - yashpatelphd/CVE-2024-30695
π¨ CVE-2024-30696
OS command injection vulnerability in ROS2 Galactic Geochelone in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the command processing or system call components in ROS2, including External Command Execution Modules, System Call Handlers, and Interface Scripts.
π@cveNotify
OS command injection vulnerability in ROS2 Galactic Geochelone in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the command processing or system call components in ROS2, including External Command Execution Modules, System Call Handlers, and Interface Scripts.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30696: OS Command Injection Vulnerability in ROS2 Galactic Geochelone
OS Command Injection Vulnerability in ROS2 Galactic Geochelone - yashpatelphd/CVE-2024-30696
π¨ CVE-2024-30697
An issue was discovered in ROS2 Galactic Geochelone in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, where the system transmits messages in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.
π@cveNotify
An issue was discovered in ROS2 Galactic Geochelone in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, where the system transmits messages in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30697: Information Leakage in ROS2 Galactic Geochelone via Plaintext Message Transmission
Information Leakage in ROS2 Galactic Geochelone via Plaintext Message Transmission - yashpatelphd/CVE-2024-30697
π¨ CVE-2024-30699
A buffer overflow vulnerability has been discovered in the C++ components of ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a denial of service (DoS) via improper handling of arrays or strings.
π@cveNotify
A buffer overflow vulnerability has been discovered in the C++ components of ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a denial of service (DoS) via improper handling of arrays or strings.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30699: Buffer Overflow Vulnerability in ROS2 Galactic Geochelone
Buffer Overflow Vulnerability in ROS2 Galactic Geochelone - yashpatelphd/CVE-2024-30699
π¨ CVE-2024-30701
An insecure logging vulnerability in ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to obtain sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.
π@cveNotify
An insecure logging vulnerability in ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to obtain sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.
π@cveNotify
GitHub
GitHub - yashpatelphd/CVE-2024-30701: Insecure Logging Vulnerability in ROS2 Galactic Geochelone
Insecure Logging Vulnerability in ROS2 Galactic Geochelone - yashpatelphd/CVE-2024-30701
π¨ CVE-2024-31365
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type Builder (PTB) allows Reflected XSS.This issue affects Post Type Builder (PTB): from n/a through 2.0.8.
π@cveNotify
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type Builder (PTB) allows Reflected XSS.This issue affects Post Type Builder (PTB): from n/a through 2.0.8.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Post Type Builder (PTB) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2024-31366
Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.
π@cveNotify
Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.
π@cveNotify
Patchstack
WordPress Post Type Builder (PTB) plugin < 2.1.4 - Subscriber+ Arbitrary Post/Page Creation vulnerability - Patchstack
Hand curated, verified and enriched vulnerability information by Patchstack security experts. Find all WordPress plugin, theme and core security issues.
π¨ CVE-2021-28656
Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
π@cveNotify
Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
π@cveNotify
π¨ CVE-2022-47894
Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
For more information, the fix already was merged in the source code but Zeppelin decided to retire the SAP component
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
π@cveNotify
Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
For more information, the fix already was merged in the source code but Zeppelin decided to retire the SAP component
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
π@cveNotify
GitHub
[ZEPPELIN-5665] rework xml factory by pjfanning Β· Pull Request #4302 Β· apache/zeppelin
What is this PR for?
A few sentences describing the overall goals of the pull request's commits.
First time? Check out the contributing guide - https://zeppelin.apache.org/contribution/cont...
A few sentences describing the overall goals of the pull request's commits.
First time? Check out the contributing guide - https://zeppelin.apache.org/contribution/cont...
π¨ CVE-2024-31862
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.
Users are recommended to upgrade to version 0.11.0, which fixes the issue.
π@cveNotify
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.
Users are recommended to upgrade to version 0.11.0, which fixes the issue.
π@cveNotify
GitHub
[HOTFIX] Validate note name by jongyoul Β· Pull Request #4632 Β· apache/zeppelin
What is this PR for?
Checking invalid note name like './';
What type of PR is it?
Hot Fix
Todos
- Add validation logic for note names
What is the Jira issue?
N/A
How should thi...
Checking invalid note name like './';
What type of PR is it?
Hot Fix
Todos
- Add validation logic for note names
What is the Jira issue?
N/A
How should thi...
π¨ CVE-2024-3046
In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the session id of an authenticated user reported in logs.
This issue affects org.eclipse.kura:org.eclipse.kura.web2 version range [2.0.600, 2.4.0], which is included in Eclipse Kura version range [5.0.0, 5.4.1]
π@cveNotify
In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the session id of an authenticated user reported in logs.
This issue affects org.eclipse.kura:org.eclipse.kura.web2 version range [2.0.600, 2.4.0], which is included in Eclipse Kura version range [5.0.0, 5.4.1]
π@cveNotify
GitLab
Eclipse Kura LogServlet vulnerability (#188) Β· Issues Β· Eclipse Projects Security / vulnerability-reports Β· GitLab
Basic information Project name: Eclipse Kura Project id: iot.kura What are the...