Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2022
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
CVSS Score
5.3
EPSS Score
0.003
Published
2022-02-25
An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.
CVSS Score
5.4
EPSS Score
0.002
Published
2022-02-25
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-25
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-25
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above
CVSS Score
5.0
EPSS Score
0.0
Published
2022-02-25
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.
CVSS Score
7.5
EPSS Score
0.0
Published
2022-02-25
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.
CVSS Score
8.8
EPSS Score
0.021
Published
2022-02-25
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.2 or later.
CVSS Score
6.1
EPSS Score
0.071
Published
2022-02-25
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.
CVSS Score
6.1
EPSS Score
0.047
Published
2022-02-25
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
4.3
EPSS Score
0.002
Published
2022-02-25


Contact Us

Shodan ® - All rights reserved