Security Vulnerabilities
- CVEs Published In January 2020
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
PQI AirCard has persistent XSS
Transcend WiFiSD 1.8 has persistent XSS
FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability
AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request
AultWare pwStore 2010.8.30.0 has XSS
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.