Impact
Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after max_spider_size (default: 10M) bytes ha…
[deepmerge-ts] Prototype Pollution in deepmerge-ts
deepmerge-ts is used to merge 2 or more objects respecting type information. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). A fix was released in version 4.0.2. Currently, there is no known work…
[irrd] Improper Removal of Sensitive Information Before Storage or Transfer in irrd
IRRd did not always filter password hashes in query responses relating to mntner objects and database exports. This may have allowed adversaries to retrieve some of these hashes, perform a brute-force search for the clear-text passphrase, and use these…
[wasmtime] Use after free in Wasmtime
There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and enabling epoch interruption in Wasmtime. If you are not explicitly enabling epoch interruption (it is disabled by default) then you are not affected. If…
[vditor] Cross-site Scripting in vditor
Cross-site Scripting (XSS) – Stored in GitHub repository vanessa219/vditor prior to 3.8.13.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-0350
https://github.com/vanessa219/vditor/commit/e912e36ea98251d700499b1ac7702708d3398476
https://huntr.de…
[wpanel/wpanel4-cms] Unrestricted Upload of File with Dangerous Type in WPanel 4
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard’s Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.
References
https://nvd…
[dolibarr/dolibarr] SQL Injection in Dolibarr
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
References
https://nvd.nist.gov/vuln/detail/CVE-2021-36625
https://github.com/Dolibarr/do…
[asciidoctor-include-ext] Command Injection vulnerability in asciidoctor-include-ext
Impact
Applications using Asciidoctor (Ruby) with asciidoctor-include-ext (prior to version 0.4.0), which render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. This attac…
[express-openid-connect] URL Redirection to Untrusted Site (‘Open Redirect’) in express-openid-connect
Impact
Users of the requiresAuth middleware, either directly or through the default authRequired option, are vulnerable to an Open Redirect when the middleware is applied to a catch all route.
If all routes under example.com are protected with the requ…
[Simple-Wayland-HotKey-Daemon] Data Loss/Denial of Service in SWHKD
SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service. A patch is available on the 1.1.0 branch of the repository.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-27816
https://github.com/waycrate/sw…