CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Github link:
https://github.com/cypherlobo/DirtyPipe-BSI
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Github link:
https://github.com/cypherlobo/DirtyPipe-BSI
GitHub
GitHub - cypherlobo/DirtyPipe-BSI: A root exploit for CVE-2022-0847 (Dirty Pipe)
A root exploit for CVE-2022-0847 (Dirty Pipe). Contribute to cypherlobo/DirtyPipe-BSI development by creating an account on GitHub.
CVE-2024-4956
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
Github link:
https://github.com/art-of-defence/CVE-2024-4956
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
Github link:
https://github.com/art-of-defence/CVE-2024-4956
GitHub
GitHub - art-of-defence/CVE-2024-4956: Detection and exploitation scripts for CVE-2024-4956
Detection and exploitation scripts for CVE-2024-4956 - art-of-defence/CVE-2024-4956
Ура, мы набрали 100 подписчиков😊
Спасибо, что подписаны. Честно говоря не думал, что вообще кому то нужен этот мониторинг )
——————
Yay, we hit 100 subscribers😊
Thank you for subscribing. Honestly didn't think anyone needed this monitoring at all )
Спасибо, что подписаны. Честно говоря не думал, что вообще кому то нужен этот мониторинг )
——————
Yay, we hit 100 subscribers
Thank you for subscribing. Honestly didn't think anyone needed this monitoring at all )
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2