|
208641
|
6.5 |
MEDIUM
Network
|
ceph redhat opensuse canonical
|
ceph openshift_container_storage leap ubuntu_linux
|
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-1700
|
2024-11-21 14:11 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208642
|
5.4 |
MEDIUM
Network
|
otrs
|
otrs
|
The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-1768
|
2024-11-21 14:11 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208643
|
8.1 |
HIGH
Network
|
apache
|
spamassassin
|
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. Th…
|
CWE-78
OS Command
|
CVE-2020-1931
|
2024-11-21 14:11 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208644
|
8.1 |
HIGH
Network
|
apache
|
spamassassin
|
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-1180…
|
CWE-78
OS Command
|
CVE-2020-1930
|
2024-11-21 14:11 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208645
|
7.5 |
HIGH
Network
|
apache
|
jackrabbit_oak
|
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2020-1940
|
2024-11-21 14:11 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208646
|
6.1 |
MEDIUM
Network
|
apache
|
nifi
|
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in othe…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1933
|
2024-11-21 14:11 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208647
|
6.5 |
MEDIUM
Network
|
apache
|
superset
|
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed pa…
|
NVD-CWE-noinfo
|
CVE-2020-1932
|
2024-11-21 14:11 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208648
|
5.3 |
MEDIUM
Network
|
apache
|
nifi
|
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a s…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-1928
|
2024-11-21 14:11 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208649
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_v30_firmware
|
Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another applicati…
|
CWE-287
Improper Authentication
|
CVE-2020-1788
|
2024-11-21 14:11 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208650
|
6.0 |
MEDIUM
Local
|
huawei
|
mate_20_firmware
|
HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to…
|
CWE-287
Improper Authentication
|
CVE-2020-1840
|
2024-11-21 14:11 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|