Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-32681PUBLISHED: 2023-05-26
Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to reattach the `Proxy-Authorization` header to requests. For HTTP connections sent t...
CVE-2023-2283PUBLISHED: 2023-05-26
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the re...
CVE-2023-22970PUBLISHED: 2023-05-26Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
CVE-2023-32318PUBLISHED: 2023-05-26
Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other account the previous ses...
CVE-2023-20868PUBLISHED: 2023-05-26NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.