Skip to content
  • coron
  • coron

Gadget Gate

Header Image
Author

GitHub

589 Posts

Featured

Posted byGitHub
[semantic-release] Exposure of Sensitive Information to an Unauthorized Actor in semantic-release
Posted byGitHub
[cookiecutter] OS Command Injection in cookiecutter
Posted byGitHub
[mechanize] Authorization header leak on port redirect in mechanize
Posted byGitHub
[guzzlehttp/guzzle] Failure to strip the Cookie header on change in host or HTTP downgrade

[net.mingsoft:ms-mcms] Cross Site Request Forgery in Mingsoft MCMS

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202204/27/2022

MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-27340
https://github.com/UDKI11/vu…

[git-interface] Command injection in git-interface

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202204/30/2022

A command injection vulnerability exists in git-interface in the GitHub repository yarkeev/git-interface prior to 2.1.2. If both the git remote and destination directory are provided by user input, then the use of an –upload-pack command-line argument…

[shopware/platform] Improper Access Control in Shopware

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202204/23/2022

Impact
Permissions set to sales channel context by admin-api are still useable within normal user session
Patches
We recommend updating to the current version 6.4.10.1. You can get the update to 6.4.10.1 regularly via the Auto-Updater or directly via t…

[shopware/platform] Server-Side Request Forgery (SSRF) in Shopware

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202204/23/2022

Impact
The attacker can abuse the Admin SDK functionality on the server to read or update internal resources.
Patches
We recommend updating to the current version 6.4.10.1. You can get the update to 6.4.10.1 regularly via the Auto-Updater or directly …

[pocketmine/pocketmine-mp] Insufficient type validation in pocketmine/pocketmine-mp

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202204/27/2022

When an inventory interaction is performed (e.g. moving an item around an inventory), the client sends a serialized version of the itemstack to the server, which the server then deserializes and compares against its own copy. If the copies don’t match,…

[github.com/swaggo/http-swagger] Denial of Service in http-swagger

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202204/29/2022

Impact
Allows an attacker to perform a DOS attack consisting of memory exhaustion on the host system.
Patches
Yes. Please upgrade to v1.2.6.
Workarounds
A workaround is to restrict the path prefix to the “GET” method. As shown below
func main() {
r…

[PyPDF2] Manipulated inline images can cause Infinite Loop in PyPDF2

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202204/23/2022

Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop if the PyPDF2 user wrote the following code:
from PyPDF2 import PdfFileReader, PdfFileWriter
from PyPDF2.pdf import ContentStream

reader = PdfFileReader(“ma…

[next-auth] NextAuth.js default redirect callback vulnerable to open redirects

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202205/03/2022

next-auth v3 users before version 3.29.2 are impacted. (We recommend upgrading to v4 in most cases. See our migration guide).next-auth v4 users before version 4.3.2 are impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are no…

[django-mfa3] Improper Authentication in django-mfa3

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/202204/23/2022

Impact
django-mfa3 is a library that implements multi factor authentication for the django web framework. It achieves this by modifying the regular login view. Django however has a second login view for its admin area. This second login view was not mo…

[github.com/cri-o/cri-o] Incorrect Default Permissions in CRI-O

  • Posted inUncategorized
  • Posted byGitHub
  • 04/23/2022

Impact
A bug was found in CRI-O where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabiliti…

Posts navigation

Previous Posts 1 … 34 35 36 37 38 … 59 Next Posts
Gadget Gate
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close