Path Traversal in XWiki Platform

### Impact One can ask for any file located in the classloader using the template API and a path with ".." in it. For example ``` {{template name="../xwiki.hbm.xml"/}} ``` To our knownledge none of t ...

Continue Reading
maven:3.6 security update

maven-shared-utils [3.2.1-0.4] - Build with OpenJDK 8Read More ...

Continue Reading
maven:3.5 security update

maven-shared-utils [3.2.1-0.2] - Fix commandline injection vulnerability - Resolves: CVE-2022-29599Read More ...

Continue Reading
Weak private key generation in SSH.NET

During an **X25519** key exchange, the client’s private is generated with [**System.Random**](https://docs.microsoft.com/en-us/dotnet/api/system.random): ```cs var rnd = new Random(); _privateKey = n ...

Continue Reading
Connecting to a private network from GitHub-hosted Actions runners

GitHub Actions is a powerful tool for automating your development workflows, including CI/CD. There’s several options for where those workflows run, but GitHub-hosted runners can seem particularly ma ...

Continue Reading
[SECURITY] Fedora 36 Update: mingw-pcre2-10.40-1.fc36

Cross compiled Perl-compatible regular expression library for use with ming w32. PCRE has its own native API, but a set of "wrapper" functions that are base d on the POSIX API are also supplied in th ...

Continue Reading
This Week in Spring – May 31st, 2022

Hi, Spring fans! And welcome to another installment of _This Week in Spring_! I've just returned from three wonderful weeks overseas and now, I'm pleased as punch to convey, that I'm _home_! And hopef ...

Continue Reading
[SECURITY] [DLA 3037-1] libjpeg-turbo security update

------------------------------------------------------------------------- Debian LTS Advisory DLA-3037-1 [email protected] https://www.debian.org/lts/security/ ...

Continue Reading

Back to Main

Subscribe for the latest news: