https://security-tracker.debian.org/tracker/DSA-5784-1
Мы подготовили крупное обновление Infostart Toolkit Air – версию, ориентированную на работу с новой платформой 1С:Предприятие 8.5, более удобный интерфейс и расширение повседневных инструментов разработчика.В новой версии Toolkit Air доработаны формы, редакторы, консоли кода и запросов,…
signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.