Autore: Angelo Barbosa

CVE-2023-42505 | Apache Superset up to 2.x Database Connection Metadata information disclosure

A vulnerability was found in Apache Superset up to 2.x. It has been rated as problematic. This issue affects some unknown processing of the component Database Connection Metadata Handler. The manipulation leads to information disclosure. The identification of this vulnerability is CVE-2023-42505. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-42502 | Apache Superset up to 2.x HTTP Host Header redirect

A vulnerability was found in Apache Superset up to 2.x. It has been declared as problematic. This vulnerability affects unknown code of the component HTTP Host Header Handler. The manipulation leads to open redirect. This vulnerability was named CVE-2023-42502. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-49062 | Facebook Katran IP Header bpf_xdp_adjust_head Identification initialization

A vulnerability was found in Facebook Katran. It has been classified as problematic. This affects the function bpf_xdp_adjust_head of the component IP Header Handler. The manipulation of the argument Identification leads to improper initialization. This vulnerability is uniquely identified as CVE-2023-49062. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to apply a patch to fix this...

Per saperne di più

CVE-2023-46589 | Apache Tomcat up to 8.5.95/9.0.82/10.1.15/11.0.0-M10 HTTP Trailer Header request smuggling

A vulnerability was found in Apache Tomcat up to 8.5.95/9.0.82/10.1.15/11.0.0-M10 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Trailer Header Handler. The manipulation leads to http request smuggling. This vulnerability is handled as CVE-2023-46589. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2022-41678 | Apache ActiveMQ up to 5.16.5/5.17.3 deserialization

A vulnerability has been found in Apache ActiveMQ up to 5.16.5/5.17.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest. The manipulation leads to deserialization. This vulnerability is known as CVE-2022-41678. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più