<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CVEs on Anthony Weems</title>
    <link>https://amlw.dev/cve/</link>
    <description>Recent content in CVEs on Anthony Weems</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 22 Apr 2022 00:00:00 +0000</lastBuildDate><atom:link href="https://amlw.dev/cve/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CVE-2021-25746: Ingress-nginx directive injection via annotations</title>
      <link>https://amlw.dev/cve/cve-2021-25746/</link>
      <pubDate>Fri, 22 Apr 2022 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2021-25746/</guid>
      <description>A user that can create or update ingress objects can use &lt;code&gt;.metadata.annotations&lt;/code&gt;
in an Ingress object (in the &lt;code&gt;networking.k8s.io&lt;/code&gt; or &lt;code&gt;extensions&lt;/code&gt; API group)
to obtain the credentials of the ingress-nginx controller. In the default
configuration, that credential has access to all secrets in the cluster.</description>
    </item>
    
    <item>
      <title>CVE-2022-21496: Improper Implementation of the LDAP URI Specification Allowing for Host Validation Bypasses</title>
      <link>https://amlw.dev/cve/cve-2022-21496/</link>
      <pubDate>Tue, 19 Apr 2022 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2022-21496/</guid>
      <description>A parser differential between &lt;code&gt;com.sun.jndi.ldap.LdaoURL&lt;/code&gt; and &lt;code&gt;java.net.URI&lt;/code&gt; may lead
to LDAP URI validation bypasses.</description>
    </item>
    
    <item>
      <title>CVE-2022-21701: Istio Privileged Escalation in Kubernetes Gateway API</title>
      <link>https://amlw.dev/cve/cve-2022-21701/</link>
      <pubDate>Tue, 18 Jan 2022 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2022-21701/</guid>
      <description>Istio version 1.12.0 and 1.12.1 are vulnerable to a privilege escalation
attack. Users who have CREATE permission for
gateways.gateway.networking.k8s.io objects can escalate this privilege to
create other resources that they may not have access to, such as Pod.</description>
    </item>
    
    <item>
      <title>CVE-2019-18818: strapi Password Reset Auth Bypass</title>
      <link>https://amlw.dev/cve/cve-2019-18818/</link>
      <pubDate>Thu, 07 Nov 2019 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2019-18818/</guid>
      <description>strapi before 3.0.0-beta.17.5 mishandles password resets within
default authentication controllers.</description>
    </item>
    
    <item>
      <title>CVE-2019-1003040: Jenkins Script Security plugin sandbox escape</title>
      <link>https://amlw.dev/cve/cve-2019-1003040/</link>
      <pubDate>Thu, 28 Mar 2019 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2019-1003040/</guid>
      <description>Sandbox projection in the &amp;ldquo;Script Security and Pipeline: Groovy Plugins&amp;rdquo;
could be circumvented through methods supporting type casts and type
coercion. This allowed attackers to invoke constructors for arbitrary
types.</description>
    </item>
    
    <item>
      <title>CVE-2018-2813: MySQL Missing Privilege Check</title>
      <link>https://amlw.dev/cve/cve-2018-2813/</link>
      <pubDate>Fri, 15 Dec 2017 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2018-2813/</guid>
      <description>Privilege escalation in MySQL server due to a missing file
permission check.</description>
    </item>
    
    <item>
      <title>CVE-2016-7063: Pritunl Privilege Escalation via Path Traversal</title>
      <link>https://amlw.dev/cve/cve-2016-7063/</link>
      <pubDate>Tue, 23 Aug 2016 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2016-7063/</guid>
      <description>The Pritunl Client service accepted configuration data which was
saved to a file. The service, running as root, would write user specified
data to the user specified path, leading to privilege escalation.</description>
    </item>
    
    <item>
      <title>CVE-2016-7064: Pritunl Invalid Signature Verification</title>
      <link>https://amlw.dev/cve/cve-2016-7064/</link>
      <pubDate>Tue, 23 Aug 2016 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2016-7064/</guid>
      <description>The Pritunl Client did not validate VPN server certificates before
initiating a VPN connection.</description>
    </item>
    
    <item>
      <title>CVE-2016-4991: Command injection in NodePDF</title>
      <link>https://amlw.dev/cve/cve-2016-4991/</link>
      <pubDate>Tue, 24 May 2016 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2016-4991/</guid>
      <description>NodePDF passes filenames to child_process.exec(), however, it does not
properly encode all special characters.</description>
    </item>
    
    <item>
      <title>CVE-2015-5238: Stack overflow in libtre5</title>
      <link>https://amlw.dev/cve/cve-2015-5238/</link>
      <pubDate>Wed, 01 Jul 2015 00:00:00 +0000</pubDate>
      
      <guid>https://amlw.dev/cve/cve-2015-5238/</guid>
      <description>A buffer overflow exists in tre_parse() when parsing a literal
(e.g. \x{deadbeef}), used during regular expression compilation.</description>
    </item>
    
  </channel>
</rss>
