Path Traversal in XWiki Platform

### Impact One can ask for any file located in the classloader using the template API and a path with ".." in it. For example ``` {{template name="../xwiki.hbm.xml"/}} ``` To our knownledge none of t ...

Continue Reading
CVE-2022-30190

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability.Read More ...

Continue Reading
CVE-2022-31022

Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s ...

Continue Reading
CVE-2022-30128

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30127.Read More ...

Continue Reading
CVE-2022-30127

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30128.Read More ...

Continue Reading
CVE-2022-26905

Microsoft Edge (Chromium-based) Spoofing Vulnerability.Read More ...

Continue Reading
maven:3.5 security update

maven-shared-utils [3.2.1-0.2] - Fix commandline injection vulnerability - Resolves: CVE-2022-29599Read More ...

Continue Reading
maven:3.6 security update

maven-shared-utils [3.2.1-0.4] - Build with OpenJDK 8Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: