
CVE-2022-31053 – Signature forgery in Biscuit
https://notcve.org/view.php?id=CVE-2022-31053
13 Jun 2022 — Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any access level. The version 2 of the specification mandates a different algorithm than gamma signatures and as such is not affected by this vulnerability. The Biscuit implementations in Rust, Haskell, Go, Java and Javascript all have pu... • https://eprint.iacr.org/2020/1484 • CWE-347: Improper Verification of Cryptographic Signature •

CVE-2021-46200
https://notcve.org/view.php?id=CVE-2021-46200
21 Jan 2022 — An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php. Se presenta una vulnerabilidad de inyección SQL en Sourcecodester Simple Music Clour Community System versión 1.0, por medio del parámetro email en el archivo /music/ajax.php • https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/oretnom23/2022/Simple-Music-Cloud-Community-System • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2020-21139
https://notcve.org/view.php?id=CVE-2020-21139
04 Nov 2021 — EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add. Se ha detectado que EC Cloud E-Commerce System versión v1.3, contiene una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) que permite a atacantes añadir arbitrariamente cuentas de administrador por medio de /admin.html?do=user&act=add • https://github.com/Ryan0lb/EC-cloud-e-commerce-system-CVE-application/blob/master/README.md • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2020-5422 – UAA password may appear in BOSH System Metrics Server process arguments
https://notcve.org/view.php?id=CVE-2020-5422
02 Oct 2020 — BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details). BOSH System Metrics Server versiones anteriores a 0.1.0, exponían la contraseña UAA como un flag para un proceso que es ejecutado en el director de BOSH. Expuso la contraseña a cualquier usuario o proceso con acceso a la misma VM (por medio de ps o observando ... • https://www.cloudfoundry.org/blog/cve-2020-5422 • CWE-214: Invocation of Process Using Visible Sensitive Information CWE-668: Exposure of Resource to Wrong Sphere •

CVE-2019-11271 – Bosh Deployment logs leak sensitive information
https://notcve.org/view.php?id=CVE-2019-11271
18 Jun 2019 — Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest. Cloud Foundry BOSH versión 270.x anteriores a v270.1.1, contienen un Director BOSH que no corrige las credenciales cuando se configura para usar una base de datos MySQL. Un usuario malicioso autenticado local puede leer cualquier credencial que esté c... • https://www.cloudfoundry.org/blog/cve-2019-11271 • CWE-522: Insufficiently Protected Credentials CWE-532: Insertion of Sensitive Information into Log File •

CVE-2018-15800 – Timing attack allows extraction of signing key in Bits Service
https://notcve.org/view.php?id=CVE-2018-15800
10 Dec 2018 — Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage. En ParsePayloadHeader de payload_metadata.cc, hay una posible escritura fuera de límites debido a un desbordamiento de enteros. Esto podría llevar a un escalado de privilegios remoto sin necesitar privilegios de ejecución adicionales. No se neces... • https://www.cloudfoundry.org/blog/cve-2018-15800 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-15755 – CF networking internal policy server SQL injection
https://notcve.org/view.php?id=CVE-2018-15755
12 Oct 2018 — Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server. Cloud Foundry CF Networking Release, en versiones 2.11.0 anteriores a la 2.16.0, contiene un endpoint de API interno vulnerable a una inyección SWL entre las celdas Diego y el servidor de políticas. Un usuario aute... • https://www.cloudfoundry.org/blog/cve-2018-15755 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2018-11083 – Bosh accepts refresh tokens in place of an access token
https://notcve.org/view.php?id=CVE-2018-11083
05 Oct 2018 — Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prior to v267.2.0, allows refresh tokens to be as access tokens when using UAA for authentication. A remote attacker with an admin refresh token given by UAA can be used to access BOSH resources without obtaining an access token, even if their user no longer has access to those resources. Cloud Foundry BOSH, en versiones v264 anteriores a la v264.14.0, versiones v265 anteriores a la v265.7.0, ... • https://www.cloudfoundry.org/blog/cve-2018-11083 •

CVE-2018-13519
https://notcve.org/view.php?id=CVE-2018-13519
09 Jul 2018 — The mint function of a smart contract implementation for DigitalCloudToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. La función mintToken de una implementación de contrato inteligente para DigitalCloudToken, un token de Ethereum, tiene un desbordamiento de enteros que permite al propietario del contrato establecer cualquier valor para el balance de un usuario arbitrario. • https://github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflow.md • CWE-190: Integer Overflow or Wraparound •

CVE-2017-4961
https://notcve.org/view.php?id=CVE-2017-4961
13 Jun 2017 — An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities." Se detectó un problema en las versiones de BOSH versión 261.x anteriores a 261.3 y en todas las versiones de 260.x de Cloud Foundry Foundation. En ciertos casos, un usuario Director identi... • https://www.cloudfoundry.org/cve-2017-4961 • CWE-354: Improper Validation of Integrity Check Value •