Our web Application is going to live next month!! We can't afford any security issues after launch.

e-Securitylabs's application security assessments will provide you with an objective review and analysis, ultimately providing you with the assurance that your critical application can withstand common Internet and internal threats.

I need to know the bottom line. Can someone break into my mobile!!!

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

We got hacked. Is there anyone who can help us in this situation???

e-Securitylabs helps in finding the real root cause of the issue as well as ensures that it will not happen again.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Showing posts with label Vulnerabilities. Show all posts
Showing posts with label Vulnerabilities. Show all posts

Tuesday, 6 August 2024

Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution vulnerability

Severity: Zero day

Date of Publish: 06,Aug'24

Affected System:

Apache OFBiz: through 18.12.14

Summary

Apache OFBiz open-source enterprise resource planning ERP Allows Remote Code Execution vulnerability

Description

a zero-day pre-authentication remote code execution vulnerability was  identified  in the Apache OFBiz open-source enterprise resource planning (ERP) system that could allow remote attacker to execute arbitrary code in the affected systems..

Recommendations /Solutions

upgrade to version 18.12.15

 

Vendor Reference:

https://issues.apache.org/jira/browse/OFBIZ-13128
https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w
https://ofbiz.apache.org/download.html
https://ofbiz.apache.org/security.html

 

CVE:

CVE-2024-38856


NOTE : The information is provide is on “as is “ basis, without assurance of any kind .

 Revision history

1. 06-Aug-24 - First advisory released. ---update -update version avaible

 

Friday, 21 June 2024

Multiple vulnerbilities in Redhat Enterprise Linux

Date:June 21,2024

Severity:Medium

Impacted system

  • Red Hat Enterprise Linux for x86_64
  • Red Hat Enterprise Linux for ARM 64
  • Red Hat Enterprise Linux for Power, little endian
  • Red Hat Enterprise Linux for IBM z Systems
  • Red Hat Enterprise Linux Fast Datapath (for IBM z Systems)
  • Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE)
  • Red Hat Enterprise Linux Fast Datapath
  • Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64)
  • Red Hat Service Interconnect
  • Red Hat OpenShift Serverless for IBM Z and LinuxONE
  • Red Hat Openshift Serverless
  • Red Hat Openshift Serverless for ARM
  • Red Hat OpenShift Serverless for IBM Power, little endian
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
  • Red Hat Enterprise Linux Server - TUS
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian
  • Red Hat Enterprise Linux Server
  • Red Hat Enterprise Linux Desktop
  • Red Hat Enterprise Linux Workstation
  • Red Hat Enterprise Linux Server for ARM 64 - 4 years of updates
  • Red Hat Enterprise Linux Server for IBM z Systems - 4 years of updates
  • Red Hat Enterprise Linux Server - AUS
  • Red Hat CodeReady Linux Builder for ARM 64
  • Red Hat CodeReady Linux Builder for Power, little endian
  • Red Hat CodeReady Linux Builder for x86_64
  • Red Hat CodeReady Linux Builder for IBM z Systems
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
  • Red Hat Migration Toolkit for Applications

Summary

Redhat publish multiple vulnerabilities in their Redhat  enterprise linux and other system by which an attacker could allow remote code execution or take control of the affected system .

Description

RHSA-2024:4004 Important:thunderbird security update
RHSA-2024:4014 Important:ghostscript security update
RHSA-2024:4015 Important:thunderbird security update
RHSA-2024:4016 Important:thunderbird security update
RHSA-2024:4018 Important:thunderbird security update
RHSA-2024:4023 Important:Release of openshift-serverless-clients kn 1.33.0 security update & enhancements
RHSA-2024:4028 Moderate:Release of OpenShift Serverless 1.33.0 security update & enhancements
RHSA-2024:4034 Important:Red Hat Service Interconnect 1.5.4 Release security update (images)
RHSA-2024:4035 Important:ovn-2021 security update
RHSA-2024:4036 Important:thunderbird security update
RHSA-2024:4003 Important:thunderbird security update
RHSA-2024:4002 Important:thunderbird security update
RHSA-2024:4001 Important:thunderbird security update
RHSA-2024:4000 Important:ghostscript security update
RHSA-2024:3999 Important:ghostscript security update
RHSA-2024:3998 Moderate:curl security update
RHSA-2024:3989 Important:Migration Toolkit for Applications security and bug fix update

Solution

Please apply patches/fixes as recommended by vendor :

https://access.redhat.com/security/security-updates/security-advisories?q=&p=1&sort=portal_publication_date+desc&rows=10&portal_advisory_type=Security+Advisory&documentKind=Errata

Vendor Information

Redhat :

https://access.redhat.com/security/security-updates/security-advisories?q=&p=1&sort=portal_publication_date+desc&rows=10&portal_advisory_type=Security+Advisory&documentKind=Errata

NOTE : The information is provide is on “as is “ basis, without assurance of any kind 


Thursday, 20 June 2024

Multiple remote code execution in VMWare products

Multiple remote code execution in VMWare products.

Date of Publish: June 20,24

Severity:Critical

Affected Software:

  • VMware vCenter Server
  • VMware Cloud Foundation

Summary:

Multiple remote code execution vulnerabilities in VMware products  which can allow attacket to take over the contrl of the affected systems.

Description:

The list of vulnerabilities is as follows -

  • CVE-2024-37079 & CVE-2024-37080- Multiple heap-overflow vulnerabilities in the implementation of the DCE/RPC protocol that could allow a,n attacker with network access to vCenter Server can do remote code execution by sending a specially crafted network packet
  • CVE-2024-37081 - Multiple local privilege escalation vulnerabilities in VMware vCenter arising due to the misconfiguration of ("sudo") that an authenticated local user with non-administrative privileges could exploit to obtain root permissions.

Impacted CVE:

CVE-2024-37079
CVE-2024-37080
CVE-2024-37081

 Solution:

https://core.vmware.com/resource/vmsa-2024-0012-questions-answers#introduction

 

Vendor reference:

https://core.vmware.com/resource/vmsa-2024-0012-questions-answers#introduction

Broadcom:

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 

 

NOTE : The information is provide is on “as is “ basis, without assurance of any kind 

Friday, 14 June 2024

Microsoft Patch Tuesday June 2024

 Microsoft Patch Tuesday June 2024

Microsoft has released vulnerabilities for multiple products  

Date :Jun14,2024

Description
CVE Disclosed Exploited Severity CVSS Base (AVG) CVSS Temporal (AVG)
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CVE-2024-35255 No No Important 5.5 4.8
Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2024-35254 No No Important 7.1 6.2
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
CVE-2024-37325 No No Important 8.1 7.3
Azure Storage Movement Client Library Denial of Service Vulnerability
CVE-2024-35252 No No Important 7.5 6.5
Chromium: CVE-2024-5493 Heap buffer overflow in WebRTC
CVE-2024-5493 No No -    
Chromium: CVE-2024-5494 Use after free in Dawn
CVE-2024-5494 No No -    
Chromium: CVE-2024-5495 Use after free in Dawn
CVE-2024-5495 No No -    
Chromium: CVE-2024-5496 Use after free in Media Session
CVE-2024-5496 No No -    
Chromium: CVE-2024-5497 Out of bounds memory access in Keyboard Inputs
CVE-2024-5497 No No -    
Chromium: CVE-2024-5498 Use after free in Presentation API
CVE-2024-5498 No No -    
Chromium: CVE-2024-5499 Out of bounds write in Streams API
CVE-2024-5499 No No -    
DHCP Server Service Denial of Service Vulnerability
CVE-2024-30070 No No Important 7.5 6.7
GitHub: CVE-2024-29187 WiX Burn-based bundles are vulnerable to binary hijack when run as SYSTEM
CVE-2024-29187 No No Important 7.3 6.4
MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU
CVE-2023-50868 Yes No Important 7.5 6.5
Microsoft Azure File Sync Elevation of Privilege Vulnerability
CVE-2024-35253 No No Important 4.4 4.2
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-35263 No No Important 5.7 5
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2024-35248 No No Important 7.3 6.4
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
CVE-2024-35249 No No Important 8.8 7.7
Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability
CVE-2024-30072 No No Important 7.8 6.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2024-30080 No No Critical 9.8 8.5
Microsoft Office Remote Code Execution Vulnerability
CVE-2024-30101 No No Important 7.5 6.5
CVE-2024-30102 No No Important 7.3 6.4
CVE-2024-30104 No No Important 7.8 6.8
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-30103 No No Important 8.8 7.7
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-30100 No No Important 7.8 6.8
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
CVE-2024-30097 No No Important 8.8 7.7
Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2024-30089 No No Important 7.8 6.8
CVE-2024-30090 No No Important 7 6.1
Visual Studio Elevation of Privilege Vulnerability
CVE-2024-29060 No No Important 6.7 5.8
Visual Studio Remote Code Execution Vulnerability
CVE-2024-30052 No No Important 4.7 4.1
Win32k Elevation of Privilege Vulnerability
CVE-2024-30082 No No Important 7.8 6.8
CVE-2024-30087 No No Important 7.8 6.8
CVE-2024-30091 No No Important 7.8 7
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2024-30085 No No Important 7.8 7
Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2024-30076 No No Important 6.8 5.9
Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2024-30096 No No Important 5.5 4.8
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
CVE-2024-30063 No No Important 6.7 5.8
Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-30064 No No Important 8.8 7.7
CVE-2024-30068 No No Important 8.8 7.7
CVE-2024-30088 No No Important 7 6.3
CVE-2024-30099 No No Important 7 6.3
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-35250 No No Important 7.8 6.8
CVE-2024-30084 No No Important 7 6.1
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
CVE-2024-30074 No No Important 8 7.2
CVE-2024-30075 No No Important 8 7
Windows OLE Remote Code Execution Vulnerability
CVE-2024-30077 No No Important 8 7
Windows Perception Service Elevation of Privilege Vulnerability
CVE-2024-35265 No No Important 7 6.1
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2024-30069 No No Important 4.7 4.1
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-30094 No No Important 7.8 6.8
CVE-2024-30095 No No Important 7.8 6.8
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2024-30083 No No Important 7.5 6.5
Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability
CVE-2024-30062 No No Important 7.8 7
Windows Storage Elevation of Privilege Vulnerability
CVE-2024-30093 No No Important 7.3 6.4
Windows Themes Denial of Service Vulnerability
CVE-2024-30065 No No Important 5.5 4.8
Windows Wi-Fi Driver Remote Code Execution Vulnerability
CVE-2024-30078 No No Important 8.8 7.7
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2024-30086 No No Important 7.8 6.8
Winlogon Elevation of Privilege Vulnerability
CVE-2024-30066 No No Important 5.5 4.8
CVE-2024-30067 No No Important 5.5 4.8
 
Original Advisory
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability

NOTE:The Information provided is on "as is" basis, without assurance of any kind.

Wednesday, 12 June 2024

Multiple Vulnerabilities in Google ChromeOS

Multiple Vulnerabilities in Google ChromeOS

Publish Date : June 12, 24

Severity Rating: HIGH
 
Affected version:
• LTS channel for Google ChromeOS versions prior to 120.0.6099.314 (Platform Version: 15662.111)
 

Overview
Remote code execution vulnerabilities have been reported in LTS channel for ChromeOS which could be exploited by a remote attacker to execute arbitrary code on the targeted system.
 

Description
These vulnerabilities exist in LTS channel for ChromeOS Out of bounds component write in Streams API and Type Confusion in V8.A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted Web page.
Successful exploitation of these vulnerabilities could allow remote attacker to execute arbitrary code on the targeted system.
 

Solution
Apply appropriate updates as mentioned in the advisory:
https://chromereleases.googleblog.com/2024/06/long-term-support-channel-update-for_10.html
 

Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2024/06/long-term-support-channel-update-for_10.html
 

References
Google Chrome
https://chromereleases.googleblog.com/2024/06/long-term-support-channel-update-for_10.html
 

CVE Name
CVE-2024-5499
CVE-2024-5274

Tuesday, 30 April 2024

Palo Alto Networks under attack-zero-day attack

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

 

Affected version:

  • PAN-OS 11.1    < 11.1.0-h3,< 11.1.1-h1, < 11.1.2-h3                               
  • PAN-OS 11.0    < 11.0.0-h3,< 11.0.1-h4, < 11.0.2-h4, < 11.0.3-h10, < 11.0.4-h1    
  • PAN-OS 10.2    < 10.2.0-h3,< 10.2.1-h2, < 10.2.2-h5, < 10.2.3-h13, < 10.2.4-h16, < 10.2.5-h6, < 10.2.6-h3, < 10.2.7-h8, < 10.2.8-h3, < 10.2.9-h1

Summary

This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls configured with GlobalProtect gateway or GlobalProtect portal (or both). Device telemetry does not need to be enabled for PAN-OS firewalls to be exposed to attacks related to this vulnerability.

You can verify whether you have a GlobalProtect gateway or GlobalProtect portal configured by checking for entries in your firewall web interface (Network > GlobalProtect > Gateways or Network > GlobalProtect > Portals).

Solution

It is recommended to immediately upgrade to a fixed version of PAN-OS to protect their devices even when workarounds and mitigations have been applied.

issue is fixed in PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. These fixes and those listed below completely prevent the initial remote command execution, stopping subsequent post-exploitation or persistence.

In addition, to provide the most seamless upgrade path for customers, additional hotfixes have been made available as a courtesy for other commonly deployed maintenance releases.

Workarounds and Mitigations

it is suggested to use Threat Prevention subscription can block attacks for this vulnerability using Threat IDs 95187, 95189, and 95191 (available in Applications and Threats content version 8836-8695 and later). Please monitor this advisory and new Threat Prevention content updates for additional Threat Prevention IDs around CVE-2024-3400.

To apply the Threat IDs, customers must ensure that vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of this issue on their device. Please see https://live.paloaltonetworks.com/t5/globalprotect-articles/applying-vulnerability-protection-to-globalprotect-interfaces/ta-p/340184 for more information.

Reference :

Palo alto Networks

https://security.paloaltonetworks.com/CVE-2024-3400


NOTE : The information is provide is on “as is “ basis, without assurance of any kind.

 

 

 

 

 

Tuesday, 20 February 2024

Cross-site request forgery in Migrate Tools module for Drupal

Cross-site request forgery in Migrate Tools module for Drupal


Severity Rating: MEDIUM


Software Affected
• Drupal Migrate Tools version prior to 6.0.3.
 

Overview
This vulnerability has been reported in Drupal Migrate Tools module which could be exploited by the attacker to conduct Cross
site request forgery attacks to take control of the targeted system.
 

Description
This vulnerability exists in Drupal Migrate Tools due to insufficient protection against Cross Site Request Forgery attacks. An
attacker could exploit this vulnerability by tricking an authenticated administrator to initiate migration.
Successful exploitation of this vulnerability could allow the attacker to compromise the target system.
 

Solution
Apply appropriate patches as mentioned in Drupal security advisories:
https://www.drupal.org/sa-contrib-2024-008
 

Vendor Information
 

Drupal
https://www.drupal.org/sa-contrib-2024-008
 

References
Drupal

https://www.drupal.org/sa-contrib-2024-008

 

NOTE : The information is provide is on “as is “ basis, without assurance of any kind.

 

Tuesday, 26 September 2023

Apple squashes security bugs

 Apple has pushed out security updates that fix two actively exploited zero-day vulnerabilities (CVE-2023-28205, CVE-2023-28206) in macOS, iOS and iPadOS.

Affected Systems

  • macOS Monterey 12.7
  • macOS Ventura 13.6:
  • watchOS 9.6.3
  • watchOS 10.0.1:
  • iOS 16.7 and iPadOS 16.7
  • iOS 17.0.1 and iPadOS 17.0.1
  • Safari 16.6.1

Apple emitted patches this week to close security holes that have been exploited in the wild by commercial spyware.

The bugs are:

  1. CVE-2023-41991: According to Apple, "a malicious app may be able to bypass signature validation," and was fixed by correcting "a certificate validation issue."
  2. CVE-2023-41992: This is a kernel-level privilege escalation hole that was fixed "with improved checks." This can be abused by rogue applications and users to gain the necessary privileges to take full control of a device.
  3. CVE-2023-41993: Apple said "processing web content may lead to arbitrary code execution," which again was addressed "with improved checks." A maliciously crafted webpage could exploit this when someone browses that page on a vulnerable device. We could see these bugs being chained together: a webpage could inject code that elevates its privileges to kernel level to take over a system, for instance.

Each bug, according to Apple, "may have been actively exploited against versions of iOS before iOS 16.7." However, due to the way the iGiant's various products share various bits of the same code, it's not just iPhones and iOS that are vulnerable: other Apple gear is affected and ought to be patched so that further exploitation is prevented.

Solution

Apply workarounds at 

  • https://support.apple.com/en-us/HT213932
  • https://support.apple.com/kb/HT213931
  • https://support.apple.com/kb/HT213929
  • https://support.apple.com/kb/HT213928
  • https://support.apple.com/kb/HT213927
  • https://support.apple.com/kb/HT213926
  • https://support.apple.com/kb/HT213930

Original Advisory

Apple Support

https://support.apple.com/

NOTE : The information is provide is on “as is “ basis, without assurance of any kind.


Wednesday, 16 August 2023

Denial of service vulnerability in Visual Studio.Net

Microsoft Security Advisory CVE-2023-38180: .NET Denial of Service Vulnerability

Date: 16-Aug-23
Severity: Medium

Affected software

  • Any .NET 7.0 application running on .NET 7.0.8 or earlier.
  • Any .NET 6.0 application running on .NET 6.0.19 or earlier.
Description

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1, .NET 6.0, and .NET 7.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A vulnerability exists in Kestrel where, on detecting a potentially malicious client, Kestrel will sometimes fail to disconnect it, resulting in denial of service.

Solution

Apply workarounds at
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180

Original Advisory

Microsoft:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180     


 NOTE : The information is provide is on “as is “ basis, without assurance of any kind.