Use-after-free when sending SASL login to the server may affect the stability of Irssi. SASL logins may fail, especially during (manual and automated) reconnect.
Month: June 2019
ASA-2019-00400 – Magento: Arbitrary code execution via malicious XML layouts
An authenticated user with admin privileges can execute arbitrary code when creating a product via malicious XML layouts.
ASA-2019-00399 – Magento: Security bypass via form data injection
An authenticated user can inject form data and bypass security protections that prevent arbitrary PHP script upload.
ASA-2019-00398 – Magento: Arbitrary code execution via file upload in admin import feature
An authenticated user with admin privileges to the import feature can execute arbitrary code by uploading a malicious csv file.
ASA-2019-00397 – Magento: Arbitrary code execution through product imports and design layout update
An authenticated user with admin privileges can execute arbitrary code through combination of product import via crafted csv file and XML layout update.
ASA-2019-00396 – Magento: Arbitrary code execution through design layout update
An authenticated user with admin privileges can execute arbitrary code through a crafted XML layout update.
ASA-2019-00395 – Pivotal Spring Security: PlaintextPasswordEncoder authenticates encoded passwords that are null
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of “null”.
ASA-2019-00394 – Atlassian Jira: Denial of service in issue searching through Epic Name ordering
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".