|
CVE-2018-20595
|
High
|
2018-12-30
|
No exploit published
|
No public exploit
|
A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
|
|
CVE-2018-20594
|
Medium
|
2018-12-30
|
No exploit published
|
No public exploit
|
An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java.
|
|
CVE-2018-20433
|
Critical
|
2018-12-24
|
Protected by RASP
|
No public exploit
|
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
|
|
CVE-2018-17197
|
Medium
|
2018-12-24
|
No exploit published
|
No public exploit
|
A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.
|
|
CVE-2018-17247
|
Medium
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.
|
|
CVE-2018-17244
|
Medium
|
2018-12-20
|
No exploit published
|
No public exploit
|
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being authenticated concurrently; when used with run as, this can result in the request running as the incorrect user. This could allow a user to access information that they should not have access to.
|
|
CVE-2018-1000873
|
Medium
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.
|
|
CVE-2018-1000854
|
Critical
|
2018-12-20
|
No exploit published
|
No public exploit
|
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT that can result in Remote Code Execution. This attack appear to be exploitable via Use of another weakness in backend application to reflect ESI directives. This vulnerability appears to have been fixed in 5.3.
|
|
CVE-2018-1000850
|
High
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.
|
|
CVE-2018-1000844
|
Critical
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this to remotely read files from the file system or to perform SSRF.. This vulnerability appears to have been fixed in After commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437.
|
|
CVE-2018-1000836
|
Critical
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server.
|
|
CVE-2018-1000823
|
Critical
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
|
|
CVE-2018-1000822
|
Critical
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via specially crafted GSA XML files. This vulnerability appears to have been fixed in after commit faa265b.
|
|
CVE-2018-1000820
|
Critical
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.
|
|
CVE-2018-1000817
|
High
|
2018-12-20
|
Protected by RASP
|
No public exploit
|
Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in Download .class files and any arbitrary file. This attack appear to be exploitable via Specially crafted GET request containing directory traversal from assets-pipeline context. This vulnerability appears to have been fixed in 2.14.1.1 (for Grails 2.x), 2.15.1 (for Grails 3 and Java 7) and 3.0.6 (for Grails 3 and Java 8).
|
|
CVE-2018-20227
|
High
|
2018-12-19
|
Protected by RASP
|
No public exploit
|
RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.
|
|
CVE-2018-17195
|
High
|
2018-12-19
|
No exploit published
|
No public exploit
|
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication, same subnet access, and injecting malicious code into an unprotected (plaintext HTTP) website which the targeted user later visits, but the possible damage warranted a Severe severity level. Mitigation: The fix to apply Cross-Origin Resource Sharing (CORS) policy request filtering was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
|
|
CVE-2018-17194
|
High
|
2018-12-19
|
No exploit published
|
No public exploit
|
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receiving nodes would wait for the body and eventually timeout. Mitigation: The fix to check DELETE requests and overwrite non-zero Content-Length header values was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
|
|
CVE-2018-17193
|
Medium
|
2018-12-19
|
No exploit published
|
No public exploit
|
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
|
|
CVE-2018-17192
|
Medium
|
2018-12-19
|
No exploit published
|
No public exploit
|
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security headers was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
|
|
CVE-2018-15801
|
High
|
2018-12-19
|
No exploit published
|
No public exploit
|
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.
|
|
CVE-2018-11799
|
Medium
|
2018-12-19
|
No exploit published
|
No public exploit
|
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.
|
|
CVE-2018-19413
|
Medium
|
2018-12-14
|
No exploit published
|
No public exploit
|
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field to non-administrator users. The attacker could use this information in subsequent attacks against the system.
|
|
CVE-2018-20094
|
High
|
2018-12-12
|
Protected by RASP
|
No public exploit
|
An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.
|
|
CVE-2018-1926
|
High
|
2018-12-12
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability to perform CSRF attack and update available applications. IBM X-Force ID: 152992.
|
|
CVE-2018-1901
|
High
|
2018-12-12
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
|
|
CVE-2018-20059
|
Critical
|
2018-12-11
|
Protected by RASP
|
No public exploit
|
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
|
|
CVE-2018-1904
|
Critical
|
2018-12-11
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.
|
|
CVE-2018-20000
|
High
|
2018-12-10
|
Protected by RASP
|
No public exploit
|
Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.
|
|
CVE-2018-1957
|
Medium
|
2018-12-10
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.
|
|
CVE-2018-1000866
|
High
|
2018-12-10
|
No exploit published
|
No public exploit
|
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM
|
|
CVE-2018-1000865
|
High
|
2018-12-10
|
No exploit published
|
No public exploit
|
A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM, if plugins using the Groovy sandbox are installed.
|
|
CVE-2018-1000864
|
Medium
|
2018-12-10
|
No exploit published
|
No public exploit
|
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
|
|
CVE-2018-1000863
|
High
|
2018-12-10
|
Protected by RASP
|
No public exploit
|
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
|
|
CVE-2018-1000862
|
Medium
|
2018-12-10
|
No exploit published
|
No public exploit
|
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.
|
|
CVE-2018-1000861
|
Critical
|
2018-12-10
|
Protected by RASP
|
Exploited in the wild
|
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
|
|
CVE-2018-19907
|
High
|
2018-12-06
|
Protected by RASP
|
No public exploit
|
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.
|
|
CVE-2018-19859
|
Medium
|
2018-12-05
|
Protected by RASP
|
No public exploit
|
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
|
|
CVE-2018-1840
|
High
|
2018-12-03
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
|