Author: Angelo Barbosa

CVE-2023-49298 | OpenZFS up to 2.1.13/2.2.1 /etc/hosts.deny access control (ID 15526)

A vulnerability was found in OpenZFS up to 2.1.13/2.2.1 and classified as problematic. This issue affects some unknown processing of the file /etc/hosts.deny. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2023-49298. It is possible to launch the attack on the local host. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-49068 | Apache DolphinScheduler up to 3.2.0 AbstractAuthenticator.java information disclosure

A vulnerability has been found in Apache DolphinScheduler up to 3.2.0 and classified as problematic. This vulnerability affects unknown code of the file dolphinscheduler-api/src/main/java/org/apache/dolphinscheduler/api/security/impl/AbstractAuthenticator.java. The manipulation leads to information disclosure. This vulnerability was named CVE-2023-49068. Access to the local network is required for this attack. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-46575 | Meshery prior 0.6.179 order sql injection

A vulnerability, which was classified as critical, was found in Meshery. This affects an unknown part. The manipulation of the argument order leads to sql injection. This vulnerability is uniquely identified as CVE-2023-46575. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-48711 | cjvnjde google-translate-api-browser up to 4.1.2 Web API server-side request forgery (GHSA-4233-7q5q-m7p6)

A vulnerability, which was classified as problematic, has been found in cjvnjde google-translate-api-browser up to 4.1.2. Affected by this issue is some unknown functionality of the component Web API. The manipulation leads to server-side request forgery. This vulnerability is handled as CVE-2023-48711. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-48707 | CodeIgniter4 Shield up to 1.0.0-beta.7 HMAC SHA256 cleartext storage

A vulnerability classified as problematic was found in CodeIgniter4 Shield up to 1.0.0-beta.7. Affected by this vulnerability is an unknown functionality of the component HMAC SHA256 Handler. The manipulation leads to cleartext storage of sensitive information. This vulnerability is known as CVE-2023-48707. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More