Security
Headlines
HeadlinesLatestCVEs

Source

ghsa

GHSA-xhp9-4947-rq78: Denial of service in bottle

Bottle before 0.12.20 mishandles errors during early request binding.

ghsa
#dos#git
GHSA-6xj9-hpq3-w3qw: Code injection in MCMS

An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.

GHSA-4qf6-vpj8-p4r6: Cross site scripting in SSCMS

siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).

GHSA-q4qm-xhf9-4p8f: Authorization bypass in Flower

Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.

GHSA-526x-rm7j-v389: Privilege escalation in Hashicorp Nomad

HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

GHSA-23f2-vgr6-fwv7: Command injection in librenms

LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.

GHSA-8rp2-j3vj-hgj4: Cross site scripting in Jfinal

A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.

GHSA-fp36-299x-pwmw: Regular expression denial of service in devcert

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method

GHSA-mmh6-m7v9-5956: Regular expression denial of service in markdown-link-extractor

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function

GHSA-4x5v-gmq8-25ch: Regular expression denial of service in semver-regex

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method