Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 989

Количество 376 989

github логотип

GHSA-3p33-32v8-fg8j

11 дней назад

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS configuration. The project masks passwords elsewhere before display, so the omission here is inconsistent rather than intended. The UI endpoint `/api/v1/cluster/configuration` compounded this. It carried no `@AuthNimbusOp` annotation, and the authorization filter treated a missing annotation as "no gate required" and returned immediately, so the endpoint applied no per-user check at all and proxied the request under the UI daemon's own principal. Any user able to pass `ui.filter` therefore received the full configuration, including principals that Nimbus itself would have refused.  Mitigation Upgrade to 3.1.0, where credential-bearing values are masked before the configu...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p32-j457-pg5x

больше 5 лет назад

Query Binding Exploitation

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3p32-8vq4-qvph

почти 2 года назад

An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p2x-p2h6-wp37

около 4 лет назад

Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2x-hjxj-c7rv

6 месяцев назад

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p2x-hfrr-wj4w

больше 1 года назад

Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2x-fgmw-32pv

больше 2 лет назад

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p2x-2cfv-p7xm

больше 4 лет назад

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

EPSS: Низкий
github логотип

GHSA-3p2w-3263-9gr3

около 4 лет назад

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p2v-w863-5q4c

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: cdns_i2c_master_xfer(): Fix runtime PM leak on error path The cdns_i2c_master_xfer() function gets a runtime PM reference when the function is entered. This reference is released when the function is exited. There is currently one error path where the function exits directly, which leads to a leak of the runtime PM reference. Make sure that this error path also releases the runtime PM reference.

EPSS: Низкий
github логотип

GHSA-3p2v-g86r-3rwm

10 дней назад

In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3p2v-4qj8-6w5f

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-core: explicitly clear ioctl input data As seen from a recent syzbot bug report, mistakes in the compat ioctl implementation can lead to uninitialized kernel stack data getting used as input for driver ioctl handlers. The reported bug is now fixed, but it's possible that other related bugs are still present or get added in the future. As the drivers need to check user input already, the possible impact is fairly low, but it might still cause an information leak. To be on the safe side, always clear the entire ioctl buffer before calling the conversion handler functions that are meant to initialize them.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2r-ffrh-j979

8 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3p2r-95j5-h86j

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM allows Stored XSS.This issue affects Beaver Builder Addons by WPZOOM: from n/a through 1.3.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p2q-mr23-4xx4

4 месяца назад

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'project_search' parameter in all versions up to, and including, 5.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p2q-mh7q-9pxj

больше 3 лет назад

Duplicate Advisory: elFinder vulnerable to path traversal in LocalVolumeDriver connector

EPSS: Низкий
github логотип

GHSA-3p2q-4jpq-m2x2

больше 4 лет назад

The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.

EPSS: Низкий
github логотип

GHSA-3p2p-cj2p-f89p

больше 4 лет назад

A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p2p-55rm-xcvw

10 месяцев назад

A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions), Simcenter System Architect (All versions), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3p2m-vxm4-c34h

больше 4 лет назад

BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p33-32v8-fg8j

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS configuration. The project masks passwords elsewhere before display, so the omission here is inconsistent rather than intended. The UI endpoint `/api/v1/cluster/configuration` compounded this. It carried no `@AuthNimbusOp` annotation, and the authorization filter treated a missing annotation as "no gate required" and returned immediately, so the endpoint applied no per-user check at all and proxied the request under the UI daemon's own principal. Any user able to pass `ui.filter` therefore received the full configuration, including principals that Nimbus itself would have refused.  Mitigation Upgrade to 3.1.0, where credential-bearing values are masked before the configu...

CVSS3: 6.5
0%
Низкий
11 дней назад
github логотип
GHSA-3p32-j457-pg5x

Query Binding Exploitation

CVSS3: 7.2
2%
Низкий
больше 5 лет назад
github логотип
GHSA-3p32-8vq4-qvph

An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p2x-p2h6-wp37

Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3p2x-hjxj-c7rv

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

CVSS3: 6.5
6 месяцев назад
github логотип
GHSA-3p2x-hfrr-wj4w

Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p2x-fgmw-32pv

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p2x-2cfv-p7xm

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3p2w-3263-9gr3

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-3p2v-w863-5q4c

In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: cdns_i2c_master_xfer(): Fix runtime PM leak on error path The cdns_i2c_master_xfer() function gets a runtime PM reference when the function is entered. This reference is released when the function is exited. There is currently one error path where the function exits directly, which leads to a leak of the runtime PM reference. Make sure that this error path also releases the runtime PM reference.

0%
Низкий
9 месяцев назад
github логотип
GHSA-3p2v-g86r-3rwm

In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
10 дней назад
github логотип
GHSA-3p2v-4qj8-6w5f

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-core: explicitly clear ioctl input data As seen from a recent syzbot bug report, mistakes in the compat ioctl implementation can lead to uninitialized kernel stack data getting used as input for driver ioctl handlers. The reported bug is now fixed, but it's possible that other related bugs are still present or get added in the future. As the drivers need to check user input already, the possible impact is fairly low, but it might still cause an information leak. To be on the safe side, always clear the entire ioctl buffer before calling the conversion handler functions that are meant to initialize them.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3p2r-ffrh-j979

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3p2r-95j5-h86j

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM allows Stored XSS.This issue affects Beaver Builder Addons by WPZOOM: from n/a through 1.3.4.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3p2q-mr23-4xx4

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'project_search' parameter in all versions up to, and including, 5.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3p2q-mh7q-9pxj

Duplicate Advisory: elFinder vulnerable to path traversal in LocalVolumeDriver connector

больше 3 лет назад
github логотип
GHSA-3p2q-4jpq-m2x2

The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3p2p-cj2p-f89p

A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p2p-55rm-xcvw

A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions), Simcenter System Architect (All versions), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-3p2m-vxm4-c34h

BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу