Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-4143: build: use official ep_cursortrace · bigbluebutton/bigbluebutton@62040bd

Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.

CVE
#xss#redis#nodejs#git

@@ -32,9 +32,7 @@ git clone https://github.com/mconf/ep_redis_publisher.git

npm pack ./ep_redis_publisher

npm install ./ep_redis_publisher-*.tgz

npm install ep_cursortrace

using mconf’s fork due to https://github.com/ether/ep_cursortrace/pull/25 not being accepted upstream

npm install git+https://github.com/mconf/ep_cursortrace.git

npm install ep_cursortrace

npm install ep_disable_chat

For some reason installing from github using npm 7.5.2 gives

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda