Security
Headlines
HeadlinesLatestCVEs

Tag

#git

PHPJabbers Shuttle Booking Software 2.0 CSV Injection

PHPJabbers Shuttle Booking Software version 2.0 suffers from a CSV injection vulnerability.

Packet Storm
#vulnerability#windows#git#php#auth
PHPJabbers Time Slots Booking Calendar 4.0 Cross Site Scripting

PHPJabbers Time Slots Booking Calendar version 4.0 suffers from multiple persistent cross site scripting vulnerabilities.

PHPJabbers Time Slots Booking Calendar 4.0 HTML Injection

PHPJabbers Time Slots Booking Calendar version 4.0 suffers from an html injection vulnerability.

Inside America's School Internet Censorship Machine

A WIRED investigation into internet censorship in US schools found widespread use of filters to censor health, identity, and other crucial information. Students say it makes the web entirely unusable.

Social media giants to testify over failing to protect kids

US senators issued subpoenas for the CEO’s of five social media giants to testify about their "failure to protect children online".

GHSA-gm62-rw4g-vrc4: Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data

A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

A week in security (November 27 – December 3)

A list of topics we covered in the week of November 27 to December 3 of 2023

CVE-2023-5332: Consul RCE vulnerability `enable-script-checks` (#8171) · Issues · GitLab.org / omnibus-gitlab · GitLab

Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

CVE-2023-49287: Buffer overflow vulnerabilities in tinydir

TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.

CVE-2023-49948: Forgejo Security Release 1.20.5-1

Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.