Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.
Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authenticated malicious user can potentially exploit this vulnerability leading to privilege escalation by writing to a protected directory when Dell Command Monitor is installed to a non-default path
** REJECT ** This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
** REJECT ** This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
** REJECT ** This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
** REJECT ** This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
** REJECT ** This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.
Рассказываем, зачем нам это было нужно, с какими трудностями столкнулись и к чему в итоге пришли. Читать далее