CVE-2021-27582
https://notcve.org/view.php?id=CVE-2021-27582
org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow, in which HTTP request parameters affect an authorizationRequest. El archivo org/mitre/oauth2/web/OAuthConfirmationController.java en la implementación del servidor OpenID Connect para MITREid Connect versiones hasta 1.3.3, contiene una vulnerabilidad de Asignación Masiva (también se conoce como Autobinding). Esto surge debido al uso no seguro de la anotación @ModelAttribute durante el flujo de autorización de OAuth, en el que los parámetros de petición HTTP afectan a una autorización de petición • http://agrrrdog.blogspot.com/2017/03/autobinding-vulns-and-spring-mvc.html https://github.com/mitreid-connect/OpenID-Connect-Java-Spring-Server/commit/7eba3c12fed82388f917e8dd9b73e86e3a311e4c https://portswigger.net/research/hidden-oauth-attack-vectors • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') •
CVE-2020-24443 – Reflected Cross-Site Scripting (XSS) in Adobe Connect
https://notcve.org/view.php?id=CVE-2020-24443
Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Adobe Connect versión 11.0 (y anteriores) está afectada por una vulnerabilidad de tipo Cross-Site Scripting (XSS) reflejado. Si un atacante es capaz de convencer a una víctima para que visite una URL referenciando a una página vulnerable, un contenido JavaScript malicioso puede ser ejecutado en el contexto del navegador de la víctima • https://helpx.adobe.com/security/products/connect/apsb20-69.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-24442 – Reflected Cross-Site Scripting (XSS) in Adobe Connect
https://notcve.org/view.php?id=CVE-2020-24442
Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Adobe Connect versión 11.0 (y anteriores) está afectada por una vulnerabilidad de tipo Cross-Site Scripting (XSS) reflejado. Si un atacante es capaz de convencer a una víctima para que visite una URL referenciando a una página vulnerable, un contenido JavaScript malicioso puede ser ejecutado en el contexto del navegador de la víctima • https://helpx.adobe.com/security/products/connect/apsb20-69.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-9442
https://notcve.org/view.php?id=CVE-2020-9442
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there. OpenVPN Connect versión 3.1.0.361 sobre Windows, presenta Permisos No Seguros para %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, lo que permite a usuarios locales alcanzar privilegios al copiar una biblioteca drvstore.dll maliciosa. • https://github.com/hessandrew/CVE-2020-9442 • CWE-281: Improper Preservation of Permissions •
CVE-2019-19592
https://notcve.org/view.php?id=CVE-2019-19592
Jama Connect 8.44.0 is vulnerable to stored Cross-Site Scripting Jama Connect versión 8.44.0 es vulnerable a Cross-Site Scripting (XSS) almacenado • https://sumukh30.blogspot.com/2020/01/normal-0-false-false-false-en-us-x-none.html?m=1 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •