Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-35910: Require elevation to save list of plugin repositories by crobibero · Pull Request #7569 · jellyfin/jellyfin

In Jellyfin before 10.8, stored XSS allows theft of an admin access token.

CVE
#xss#auth

@@ -155,7 +155,7 @@ public ActionResult<IEnumerable<RepositoryInfo>> GetRepositories() /// <response code="204">Package repositories saved.</response> /// <returns>A <see cref="NoContentResult"/>.</returns> [HttpPost(“Repositories”)] [Authorize(Policy = Policies.DefaultAuthorization)] [Authorize(Policy = Policies.RequiresElevation)] [ProducesResponseType(StatusCodes.Status204NoContent)] public ActionResult SetRepositories([FromBody, Required] List<RepositoryInfo> repositoryInfos) {

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907