FIRST Announces Cyber-Response Ethical Guidelines

Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database CVE-2020-27621
PUBLISHED: 2020-10-22

The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inab...

PUBLISHED: 2020-10-22

The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.

PUBLISHED: 2020-10-22

In Python 3 through 3.9.0, the Lib/test/ CJK codec tests call eval() on content retrieved via HTTP.

PUBLISHED: 2020-10-21

WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it is possible to inject an XSS payload into the owner POST parameter, which does not filter user inputs. By putting an XSS payload in place of a valid Owner Name, a modal b...

PUBLISHED: 2020-10-21

Adobe InDesign version 15.1.2 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .indd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.