Author: Angelo Barbosa

CVE-2023-6293 | Robin Buschmann sequelize-typescript up to 2.1.5 prototype pollution

A vulnerability was found in Robin Buschmann sequelize-typescript up to 2.1.5. It has been classified as problematic. Affected is an unknown function. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’). This vulnerability is traded as CVE-2023-6293. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-49298 | OpenZFS up to 2.1.13/2.2.1 /etc/hosts.deny access control (ID 15526)

A vulnerability was found in OpenZFS up to 2.1.13/2.2.1 and classified as problematic. This issue affects some unknown processing of the file /etc/hosts.deny. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2023-49298. It is possible to launch the attack on the local host. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-49068 | Apache DolphinScheduler up to 3.2.0 AbstractAuthenticator.java information disclosure

A vulnerability has been found in Apache DolphinScheduler up to 3.2.0 and classified as problematic. This vulnerability affects unknown code of the file dolphinscheduler-api/src/main/java/org/apache/dolphinscheduler/api/security/impl/AbstractAuthenticator.java. The manipulation leads to information disclosure. This vulnerability was named CVE-2023-49068. Access to the local network is required for this attack. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-46575 | Meshery prior 0.6.179 order sql injection

A vulnerability, which was classified as critical, was found in Meshery. This affects an unknown part. The manipulation of the argument order leads to sql injection. This vulnerability is uniquely identified as CVE-2023-46575. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-48711 | cjvnjde google-translate-api-browser up to 4.1.2 Web API server-side request forgery (GHSA-4233-7q5q-m7p6)

A vulnerability, which was classified as problematic, has been found in cjvnjde google-translate-api-browser up to 4.1.2. Affected by this issue is some unknown functionality of the component Web API. The manipulation leads to server-side request forgery. This vulnerability is handled as CVE-2023-48711. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More