Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-32115: Known: social publishing for groups and individuals

An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.

CVE
#web#js#git#java#auth

Simple publishing

Known allows you to create and share photos, notes, stories, songs, and more. It’s easy to use and its web interface works on any device.

Features at a glance

Bookmarklet

Easily post to your site, save links, and respond to comments from any page on the web

#Tags

Use hashtags with any content to categorize and organize what you publish

Responsive Layout

View, edit, and post to your site from any device

Decentralized Indieweb

Sites can respond to each other, bookmark each others’ content and leave comments on each others’ posts

Email Notifications

Get updated whenever someone responds to a post

Feeds

Get your latest updates via RSS, XML, JSON, or KML

Multi-Author

Invite an unlimited number of collaborators and create a multi-user site

HTML & Rich Text Editor

Handcraft your posts in HTML or save time with the WYSIWYG

Custom URL

Bring your own URL and really own your site with a custom domain

Static Pages

Round out your site with static content like an about page or a contact page

Privacy

Keep your site private and create a space for your personal thoughts or a private group discussion

Custom JavaScript & CSS

Change your site’s look and add your own analytics with JavaScript and CSS editors

Any device, any place

You already spend enough time in front of a computer, and inspiration can strike anywhere. Known is fully responsive and works on whatever device you’ve got in your hand. Whether you’re sharing a sunset picture from the beach or blogging from the road, Known is there for you.

“more easily organize all your digital info in one place”

“designed to give everyone a fully open publishing platform”

“This is really how the web should be.”

Related news

GHSA-5jgj-h9wp-53fr: Known vulnerable to code execution via SVG file in v1.3.1

An issue in the isSVG() function of Known v1.3.1 allows attackers to execute arbitrary code via a crafted SVG file. The researcher report indicates that versions 1.3.1 and prior are vulnerable. Version 1.2.2 is the last version tagged on GitHub and in Packagist, and development related to the 1.3.x branch is currently on the `dev` branch of the idno/known repository.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907