CVE-2022-1941 - Protocol Buffers Parsing Vulnerability Can Lead To Out-Of-Memory Denial of Service
Imagine your service starts crashing because of a single malicious message. That’s exactly what CVE-2022-1941 is about—a parsing bug in Google&
CVE-2022-3268 Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
In the previous version, you have to provide at least 6 characters, a mix of uppercase and lowercase letters, digits and symbols. In the latest
CVE-2022-23951 Keylime's quote responses can contain untrusted ZIP data which can lead to zip bombs.
This issue has been resolved in 6.3.0.
Before upgrading to 6.3.0, make sure to disable the quote feature in your settings,
CVE-2022-31679 An attacker can access HTTP PATCH requests to the REST API in 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older versions if they know the structure of the domain model.
For example, they can use this technique to cause a service to generate a new revision of a given entity every time an HTTP request
CVE-2022-3250 An insecure cookie was placed in a HTTPS session by a GitHub repository before 2.4.6.
If a browser requests a file over HTTP instead of HTTPS, it will show a lock symbol in the URL bar. Modern browsers come with
Episode
00:00:00
00:00:00