Source
ghsa
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the `kylin.engine.spark-cmd` parameter of `conf`.
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
A vulnerability was found in pastebinit up to 0.2.2 and classified as problematic. Affected by this issue is the function pasteHandler of the file server.go. The manipulation of the argument `r.URL.Path` leads to path traversal. Upgrading to version 0.2.3 can address this issue. The name of the patch is 1af2facb6d95976c532b7f8f82747d454a092272. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217040.
### Impact The XSS vulnerability allows authenticated users to upload .html files. With that, an attacker could execute client side scripts **if** another user opened a link, such as: ``` https://push.example.org/image/[alphanumeric string].html ``` An attacker could potentially take over the account of the user that clicked the link. Keep in mind, the Gotify UI won't natively expose such a malicious link, so an attacker has to get the user to open the malicious link in a context outside of Gotify. ### Patches The vulnerability has been fixed in version 2.2.2. ### Workarounds You can block access to non image files via a reverse proxy in the `./image` directory. ### References https://github.com/gotify/server/pull/534 https://github.com/gotify/server/pull/535 --- Thanks to rickshang (aka 无在无不在) for discovering and reporting this bug.
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos 0.9.0 and prior.
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos 0.9.0 and prior.
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos 0.9.0 and prior.
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos 0.9.0 and prior.
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos 0.9.0 and prior.
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos 0.9.0 and prior.