|
Message-ID: <DM5PR14MB146504CDA1924C1B6B2479AEE1F79@DM5PR14MB1465.namprd14.prod.outlook.com> Date: Fri, 22 Apr 2022 17:49:37 +0000 From: "Myers, Christopher" <Christopher.Myers@...or.edu> To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com> Subject: CVE-2022-29464 :: WSO2 Unrestricted arbitrary file upload, and remote code to execution vulnerability. I have not seen this come across the oss-sec/CISA/DHS emails at this point, but anyone using WSO2 or a derivative needs to check this out right away. https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2021-1738 https://nvd.nist.gov/vuln/detail/CVE-2022-29464 Good writeup and PoC code here: https://github.com/hakivvi/CVE-2022-29464
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.