Red Hat Security Advisory 2022-0565-01 - Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.6.55. Issues addressed include a cross site request forgery vulnerability.
a77a27376cdeeede8e164e59332a079d3653b7b5e6c8434a66fd7fd583febb5d
Red Hat Security Advisory 2022-0672-01 - Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Issues addressed include a code execution vulnerability.
75b83c280fe30dd26b2d514ba311d51c918989f7bf0b43fc25fb89e588c8f1f0
This Metasploit module allows remote attackers to execute arbitrary code on Exchange Server 2019 CU10 prior to Security Update 3, Exchange Server 2019 CU11 prior to Security Update 2, Exchange Server 2016 CU21 prior to Security Update 3, and Exchange Server 2016 CU22 prior to Security Update 2. Note that authentication is required to exploit this vulnerability. The specific flaw exists due to the fact that the deny list for the ChainedSerializationBinder had a typo whereby an entry was typo'd as System.Security.ClaimsPrincipal instead of the proper value of System.Security.Claims.ClaimsPrincipal. By leveraging this vulnerability, attacks can bypass the ChainedSerializationBinder's deserialization deny list and execute code as NT AUTHORITY\SYSTEM. Tested against Exchange Server 2019 CU11 SU0 on Windows Server 2019, and Exchange Server 2016 CU22 SU0 on Windows Server 2016.
12eb99965a3f9b7bfde5c2c3d85628bf4f85bbe42475b654e2c35b7e33a8ccaa
Red Hat Security Advisory 2022-0665-01 - The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities. Issues addressed include a buffer over-read vulnerability.
30a40458f5e8f2144068d42968899f4d706efe71abb367d0f59cada140c422b5
Bank Management System version 1.0 suffers from a remote SQL injection vulnerability.
bb3fa2ada8dbb10e11f109d1e2eac74158f420d5db6279f49d675faf7e0c1040
Red Hat Security Advisory 2022-0669-01 - The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities. Issues addressed include a buffer over-read vulnerability.
d76b5bc5053822e21cf3d8c58b4ea3c6473c57da55a8e22f364e5f62e7fc8f79
Red Hat Security Advisory 2022-0666-01 - The cyrus-sasl packages contain the Cyrus implementation of Simple Authentication and Security Layer. SASL is a method for adding authentication support to connection-based protocols.
95dbedfb31ab478d75fd196d8c96e6aaea3383b38893a87766ecfdae1ea3a8ca
WordPress Photoswipe Masonry Gallery plugin version 1.2.14 suffers from a persistent cross site scripting vulnerability.
15996cc31605f93925a67eef5bab187429b2569dcdbb41553596502d78575f90
Red Hat Security Advisory 2022-0555-01 - Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Issues addressed include a cross site request forgery vulnerability.
04b518ab641e93f4535bdfd079f2eae5c76ff1632cf6da61dd6e81f2900b8304
Technitium Installer version 4.4 suffers from a dll hijacking vulnerability.
0e6484ed861f014968126a0f09091025cbefed6941d943a6fd29af9e7f51a890
Red Hat Security Advisory 2022-0668-01 - The cyrus-sasl packages contain the Cyrus implementation of Simple Authentication and Security Layer. SASL is a method for adding authentication support to connection-based protocols.
e0855dbe4f7074b4b32b749a55fc1193ec694d72f7ff294796c487c89cfd5991
Red Hat Security Advisory 2022-0667-01 - The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities. Issues addressed include a buffer over-read vulnerability.
dd8e0e821c9152d338037751995124bc5afa10bc5d5f918b752baac6460d2cbf
Dahua ToolBox version 1.010.0000000.0 suffers from a dll hijacking vulnerability.
13b6d80a27771213e1631636b6d01816a483271a35a812cf8beee915dd96e152