Security
Headlines
HeadlinesLatestCVEs

Source

ghsa

GHSA-jwrv-x6rx-8vfm: Macaron i18n Open Redirect vulnerability

A vulnerability was found in Macaron i18n. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file i18n.go. The manipulation leads to open redirect. The attack can be launched remotely. Upgrading to version 0.5.0 can address this issue. The name of the patch is 329b0c4844cc16a5a253c011b55180598e707735. It is recommended to upgrade the affected component. The identifier VDB-216745 was assigned to this vulnerability.

ghsa
#vulnerability#mac#git
GHSA-qqv9-gqh5-7h99: Snipe-IT allows attackers to check whether a user account exists

Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.

GHSA-363q-j92x-7543: Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets

Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.

GHSA-q6cq-m9gm-6q2f: Slixmpp lacks SSL Certificate hostname validation in XMLStream

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

GHSA-f552-97qx-c694: usememos/memos vulnerable to stored Cross-site Scripting

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

GHSA-9v48-2h5x-fvpm: POSSIBLE DUPLICATE usememos/memos vulnerable due to improper access control

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

GHSA-c8jh-vcjh-fx2w: usememos/memos vulnerable to stored cross-site scripting (XSS)

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Memos prior to 0.9.0 has a feature to upload file and display it, and by uploading a crafted SVG file, an attacker could perform a stored cross-site scripting attack with the image direct link. This was patched in version 0.9.0.

GHSA-w57v-6xp4-rm2v: usememos/memos vulnerable to account takeover due to improper access control

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Versions prior to 0.9.0 improperly maintain access control allowing an attacker to take over an account by changing header values in the HTTP request.

GHSA-vwg4-846x-f94v: usememos/memos vulnerable due to improper authentication

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Memos versions prior to 0.9.0 are vulnerable to improper authorization, which can allow a user to modify the nickname, username and email of other users without permission.

GHSA-qcw2-492v-57xj: usememos/memos missing Secure cookie attribute

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Memos prior to 0.9.0 is missing the Secure cookie attribute, making it vulnerable to session hijacking.