Security News

CVE-2019-7618

National Vulnerability Database - Tue, 10/01/2019 - 14:15
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.
Categories: Security News

CVE-2019-14961

National Vulnerability Database - Tue, 10/01/2019 - 13:15
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
Categories: Security News

CVE-2019-15042

National Vulnerability Database - Tue, 10/01/2019 - 13:15
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
Categories: Security News

CVE-2019-16942

National Vulnerability Database - Tue, 10/01/2019 - 13:15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
Categories: Security News

CVE-2019-16943

National Vulnerability Database - Tue, 10/01/2019 - 13:15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.
Categories: Security News

CVE-2019-17067

National Vulnerability Database - Tue, 10/01/2019 - 13:15
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection.
Categories: Security News

CVE-2019-17068

National Vulnerability Database - Tue, 10/01/2019 - 13:15
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
Categories: Security News

CVE-2019-17069

National Vulnerability Database - Tue, 10/01/2019 - 13:15
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message.
Categories: Security News

CVE-2019-14955

National Vulnerability Database - Tue, 10/01/2019 - 12:15
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
Categories: Security News

CVE-2019-14957

National Vulnerability Database - Tue, 10/01/2019 - 12:15
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
Categories: Security News

CVE-2019-14960

National Vulnerability Database - Tue, 10/01/2019 - 12:15
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
Categories: Security News

CVE-2019-15038

National Vulnerability Database - Tue, 10/01/2019 - 12:15
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
Categories: Security News

CVE-2019-17063

National Vulnerability Database - Tue, 10/01/2019 - 12:15
In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.
Categories: Security News

CVE-2019-17064

National Vulnerability Database - Tue, 10/01/2019 - 12:15
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
Categories: Security News

CVE-2019-14953

National Vulnerability Database - Tue, 10/01/2019 - 12:15
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
Categories: Security News

CVE-2019-10202

National Vulnerability Database - Tue, 10/01/2019 - 11:15
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
Categories: Security News

CVE-2019-11275

National Vulnerability Database - Tue, 10/01/2019 - 11:15
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.
Categories: Security News

CVE-2019-4246

National Vulnerability Database - Tue, 10/01/2019 - 11:15
IBM Daeja ViewONE Virtual 5.0 through 5.0.6 could expose internal parameters to ViewONE clients that could be used in further attacks against the system. IBM X-Force ID: 159521.
Categories: Security News

CVE-2019-4494

National Vulnerability Database - Tue, 10/01/2019 - 11:15
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164115.
Categories: Security News

CVE-2019-4495

National Vulnerability Database - Tue, 10/01/2019 - 11:15
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164116.
Categories: Security News

Pages