Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-45213: perfSONAR 4.4.6 Release Notes | perfSONAR

perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.

CVE
#js#java

Released November 9, 2022

Features/Highlighted Changes****pScheduler Fixes

  • Fixed issue where pScheduler server would look at HTTP request header when determining the local address during participant discovery. (Fixes CVE-2022-45027.)
  • Removed the ability to use the “parse” option with file:// URLs. (Fixes CVE-2022-45213.)

Graphs Fixes

  • The JavaScript frontend will now enforce the URL whitelist in graphs.json. This matches the current behavior of the backend CGI scripts.

Raw changes

Updated components:

  • graphs
  • pscheduler

Tags:

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda