CVE-2023-48427
- EPSS 0.08%
- Veröffentlicht 12.12.2023 12:15:14
- Zuletzt bearbeitet 21.11.2024 08:31:42
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the U...
CVE-2022-45094
- EPSS 0.79%
- Veröffentlicht 10.01.2023 12:15:23
- Zuletzt bearbeitet 21.11.2024 07:28:46
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially inject commands into the dhcpd configur...
CVE-2022-45093
- EPSS 1.79%
- Veröffentlicht 10.01.2023 12:15:23
- Zuletzt bearbeitet 21.11.2024 07:28:46
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product as well as with access to the SFTP server of the affected ...
CVE-2022-45092
- EPSS 21.76%
- Veröffentlicht 10.01.2023 12:15:23
- Zuletzt bearbeitet 21.11.2024 07:28:45
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and...
CVE-2022-35256
- EPSS 4.58%
- Veröffentlicht 05.12.2022 22:15:10
- Zuletzt bearbeitet 24.04.2025 14:15:32
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
CVE-2022-35255
- EPSS 1.39%
- Veröffentlicht 05.12.2022 22:15:10
- Zuletzt bearbeitet 24.04.2025 14:15:32
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, i...
CVE-2022-32213
- EPSS 89.07%
- Veröffentlicht 14.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:05:56
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
CVE-2022-32222
- EPSS 0.42%
- Veröffentlicht 14.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:05:57
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in ve...
CVE-2022-32215
- EPSS 88.11%
- Veröffentlicht 14.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:05:56
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
CVE-2022-32212
- EPSS 0.08%
- Veröffentlicht 14.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:05:56
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making D...