Month: March 2023

JetBrains Hub cross-site scripting | CVE-2022-48429

NAME__________JetBrains Hub cross-site scriptingPlatforms Affected:Risk Level:4.6Exploitability:UnprovenConsequences:Cross-Site Scripting DESCRIPTION__________JetBrains Hub is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by dashboards. A remote authenticated attacker could exploit this…

Hitachi SDM600 security bypass | CVE-2022-3683

NAME__________Hitachi SDM600 security bypassPlatforms Affected:Hitachi Energy SDM600Risk Level:7.7Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________Hitachi SDM600 could allow a remote authenticated attacker to bypass security restrictions, caused by a flaw in the API web services…

ScriptCase directory traversal | CVE-2022-32199

NAME__________ScriptCase directory traversalPlatforms Affected:ScriptCase ScriptCase 9.9.008Risk Level:3.8Exploitability:UnprovenConsequences:File Manipulation DESCRIPTION__________ScriptCase could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to…

runc denial of service | CVE-2023-25809

NAME__________runc denial of servicePlatforms Affected:Risk Level:2.5Exploitability:UnprovenConsequences:Denial of Service DESCRIPTION__________runc is vulnerable to a denial of service, caused by improper access control in the /sys/fs/cgroup endpoint. A local authenticated attacker could…