CVE-2022-3993 Authentication Bypass by Primary Weakness in GitHub repository kareadita/kavita prior to 0.6.0.3.
Credit goes to Ting Liu from Nanjgtech for reporting this. Kavita prior to 0.6.0.3 did not have any protection against user-provided information
CVE-2022-45136 Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker controls the JDBC URL or causes the underlying database server to return malicious data.
Apache Jena TDB is a drop-in replacement for Apache Jena SDB and can be used in the same applications without any changes required. The Apache
CVE-2022-45378 Apache SOAP's RPCRouterServlet has no authentication, which gives attackers the ability to invoke methods on the classpath.
Due to the fact that Apache SOAP versions 1.2, 1.3 and 1.4 are no longer supported, this vulnerability poses a critical risk
CVE-2022-27949 - Unmasking Secrets in Apache Airflow – A Hands-On Deep Dive
CVE-2022-27949 is a security flaw found in Apache Airflow's web interface, which lets attackers read unmasked (i.e., real, plain-text) secrets in rendered
CVE-2022-40127 An attacker with UI access can execute arbitrary commands via a DAG run_id parameter.
This issue is a result of a change in default configuration of DAGs when the Airflow version was upgraded from 2.3.x to 2.
Episode
00:00:00
00:00:00