IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.
Category Archives: Advisories
CVE-2022-22480
IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889.
python-django3-3.2.15-2.el8
FEDORA-EPEL-2022-0793e00396
Packages in this update:
python-django3-3.2.15-2.el8
Update description:
Updates to Django 3.2.15 which addresses https://nvd.nist.gov/vuln/detail/CVE-2022-34265 affecting Django < 3.2.14
apptainer-1.1.2-1.fc36
FEDORA-2022-0be906c02d
Packages in this update:
apptainer-1.1.2-1.fc36
Update description:
Update to 1.1.2
apptainer-1.1.2-1.el7
FEDORA-EPEL-2022-d23756a749
Packages in this update:
apptainer-1.1.2-1.el7
Update description:
Update to 1.1.2
apptainer-1.1.2-1.fc37
FEDORA-2022-f6e1ec28bf
Packages in this update:
apptainer-1.1.2-1.fc37
Update description:
Update to 1.1.2
apptainer-1.1.2-1.fc35
FEDORA-2022-2ff503c5d4
Packages in this update:
apptainer-1.1.2-1.fc35
Update description:
Update to 1.1.2
apptainer-1.1.2-1.el9
FEDORA-EPEL-2022-c5646c5693
Packages in this update:
apptainer-1.1.2-1.el9
Update description:
Update to 1.1.2
apptainer-1.1.2-1.el8
FEDORA-EPEL-2022-56c3cc55b3
Packages in this update:
apptainer-1.1.2-1.el8
Update description:
Update to 1.1.2
USN-5371-3: nginx vulnerability
USN-5371-1 and USN-5371-2 fixed several vulnerabilities in nginx.
This update provides the corresponding update for CVE-2020-11724
for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communication,
this issue could be used to redirect traffic between subdomains.
(CVE-2021-3618)