CVE-2022-22978 In Spring Security 5.5.6 and older, RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers.
attack. For example, `/^\.com$/`. Redirecting all requests to `/` with a `.` at the beginning will not match against the `/` pattern. Redirecting requests to `/` with a `.` at
CVE-2022-22784 The Zoom Client for Meetings failed to properly parse XMPP messages.
Therefore, administrators who are aware of this risk, and have their users upgrade to a newer version of the Zoom Client, should do so as
CVE-2022-1679 An use-after-free flaw was found in the Atheros wireless adapter driver, which could lead to remote code execution.
This issue affects all Linux kernel versions and will likely be fixed in a future version of the operating system.
In addition, this update fixes
CVE-2022-30781 Gitea before 1.16.7 does not escape git fetch remote.
This may leave the Gitea instance vulnerable to an attack where an attacker can add malicious code to the codebase and commit it to the
CVE-2022-1650 Unauthorized access to sensitive information in eventsource/eventsource repository before v2.0.2.
We recently discovered an issue in which unauthenticated end-users could access sensitive information, such as private SSH keys, when creating new SSH or GCE
Episode
00:00:00
00:00:00