CVE-2019-3683
published 2020-01-17CVE-2019-3683: The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the…
PriorityP348high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.94%
56.7th percentile
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | helion_openstack | — | — |
| suse | keystone-json-assignment | < 2019-02-18 | 2019-02-18 |
| suse | openstack_cloud | — | — |
| suse | suse_openstack_cloud_8 | >= keystone-json-assignment < d7888c75505465490250c00cc0ef4bb1af662f9f | d7888c75505465490250c00cc0ef4bb1af662f9f |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pfwx-2ff5-2g47: The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/ke
ghsa_unreviewed·2022-05-24
CVE-2019-3683 [MEDIUM] CWE-732 GHSA-pfwx-2ff5-2g47: The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/ke
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.
Red Hat
chromium-browser: Out-of-bounds write in V8
vendor_redhat·2019-04-30·CVSS 6.5
CVE-2019-5825 [MEDIUM] chromium-browser: Out-of-bounds write in V8
chromium-browser: Out-of-bounds write in V8
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use-after-free in IndexedDB
vendor_redhat·2019-04-30·CVSS 6.5
CVE-2019-5826 [MEDIUM] chromium-browser: Use-after-free in IndexedDB
chromium-browser: Use-after-free in IndexedDB
Use after free in IndexedDB in Google Chrome prior to 73.0.3683.86 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Integer overflow in PDFium
vendor_redhat·2019-03-12·CVSS 8.8
CVE-2019-5795 [HIGH] chromium-browser: Integer overflow in PDFium
chromium-browser: Integer overflow in PDFium
Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file.
Red Hat
chromium-browser: CSP bypass with blob URL
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-5800 [MEDIUM] chromium-browser: CSP bypass with blob URL
chromium-browser: CSP bypass with blob URL
Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Red Hat
chromium-browser: CSP bypass with Javascript URLs
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-5803 [MEDIUM] chromium-browser: CSP bypass with Javascript URLs
chromium-browser: CSP bypass with Javascript URLs
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Red Hat
chromium-browser: Out of bounds read in Skia
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-5798 [MEDIUM] chromium-browser: Out of bounds read in Skia
chromium-browser: Out of bounds read in Skia
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Statement: In general, this flaw cannot be exploited through email in Thunderbird because scripting is disabled when reading mail, but it is potentially a risk in browser or browser-like contexts.
Red Hat
chromium-browser: Security UI spoofing
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-5794 [MEDIUM] chromium-browser: Security UI spoofing
chromium-browser: Security UI spoofing
Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Red Hat
chromium-browser: CSP bypass with blob URL
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-5799 [MEDIUM] chromium-browser: CSP bypass with blob URL
chromium-browser: CSP bypass with blob URL
Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Red Hat
chromium-browser: Race condition in Extensions
vendor_redhat·2019-03-12·CVSS 7.5
CVE-2019-5796 [HIGH] chromium-browser: Race condition in Extensions
chromium-browser: Race condition in Extensions
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Heap buffer overflow in V8
vendor_redhat·2019-03-12·CVSS 8.8
CVE-2019-5790 [HIGH] chromium-browser: Heap buffer overflow in V8
chromium-browser: Heap buffer overflow in V8
An integer overflow leading to an incorrect capacity of a buffer in JavaScript in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Red Hat
chromium-browser: Command line command injection on Windows
vendor_redhat·2019-03-12·CVSS 5.5
CVE-2019-5804 [MEDIUM] chromium-browser: Command line command injection on Windows
chromium-browser: Command line command injection on Windows
Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Red Hat
chromium-browser: Incorrect Omnibox display on iOS
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-5801 [MEDIUM] chromium-browser: Incorrect Omnibox display on iOS
chromium-browser: Incorrect Omnibox display on iOS
Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Red Hat
chromium-browser: Integer overflow in PDFium
vendor_redhat·2019-03-12·CVSS 8.8
CVE-2019-5792 [HIGH] chromium-browser: Integer overflow in PDFium
chromium-browser: Integer overflow in PDFium
Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file.
Red Hat
chromium-browser: Security UI spoofing
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-5802 [MEDIUM] chromium-browser: Security UI spoofing
chromium-browser: Security UI spoofing
Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Red Hat
chromium-browser: Race condition in DOMStorage
vendor_redhat·2019-03-12·CVSS 7.5
CVE-2019-5797 [HIGH] chromium-browser: Race condition in DOMStorage
chromium-browser: Race condition in DOMStorage
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Type confusion in V8
vendor_redhat·2019-03-12·CVSS 8.8
CVE-2019-5791 [HIGH] chromium-browser: Type confusion in V8
chromium-browser: Type confusion in V8
Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: Use after free in Canvas
vendor_redhat·2019-03-12·CVSS 8.8
CVE-2019-5787 [HIGH] chromium-browser: Use after free in Canvas
chromium-browser: Use after free in Canvas
Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Excessive permissions for private API in Extensions
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-5793 [MEDIUM] chromium-browser: Excessive permissions for private API in Extensions
chromium-browser: Excessive permissions for private API in Extensions
Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page.
Red Hat
chromium-browser: Use after free in FileAPI
vendor_redhat·2019-03-12·CVSS 8.8
CVE-2019-5788 [HIGH] chromium-browser: Use after free in FileAPI
chromium-browser: Use after free in FileAPI
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
Red Hat
chromium-browser: Use after free in WebMIDI
vendor_redhat·2019-03-12·CVSS 8.8
CVE-2019-5789 [HIGH] chromium-browser: Use after free in WebMIDI
chromium-browser: Use after free in WebMIDI
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
No detection rules found.
Exploit-DB
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
exploitdb·2020-03-09
CVE-2019-5825 Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Google Chrome 72 and 73 Array.map exploit',
'Description' => %q{
This module exploits an issue in Chrome 73.0.3683.86 (64 bit).
The exploit corrupts the length of a float in order to modify the backing store
of a typed array. The typed array can then be used to read and write arbitrary
memory. The exploit then uses WebAssembly in order to allocate a region of RWX
memory, which is then replaced with the payload.
The payload is executed within the sandboxed renderer process, so the browser
must be run with the --no-sandbox option for the payload to work corr
Exploit-DB
Bematech Printer MP-4200 - Denial of Service
exploitdb·2019-11-12
Bematech Printer MP-4200 - Denial of Service
Bematech Printer MP-4200 - Denial of Service
---
# Exploit Title: Bematech Printer MP-4200 - Denial of Service
# Date: 2019-11-11
# Exploit Author: Jonatas Fil
# Vendor Homepage: https://www.bematech.com.br/
# Software Link: https://www.bematech.com.br/produto/mp-4200-th/
# Version: MP-4200 TH
# Tested on: Windows and Linux
# CVE : N/A
DoS Poc:
POST /en/conf_admin.html HTTP/1.1
Host: TARGET
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML,
like Gecko) Chrome/73.0.3683.75 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9,pt;q=0.8
Cache-Control: max-age=0
Referer: http://TARGET/en/conf_admin.html
Content-Length: 40
Content-Type: application/x-www-fo
Exploit-DB
HumHub 1.3.12 - Cross-Site Scripting
exploitdb·2019-04-30·CVSS 6.1
CVE-2019-11564 [MEDIUM] HumHub 1.3.12 - Cross-Site Scripting
HumHub 1.3.12 - Cross-Site Scripting
---
# Exploit Title: HumHub 1.3.12 - Cross-Site Scripting
# Exploit Author: Kağan EĞLENCE
# Vendor Homepage: https://humhub.org/
# Version: 1.3.12
# CVE : CVE-2019-11564
Url : http://localhost/humhub-1.3.12/protected/vendor/codeception/codeception/tests/data/app/view/index.php
Vulnerable File :
/protected/vendor/codeception/codeception/tests/data/app/view/index.php
Request Type: POST
#Request Example:
POST /humhub-1.3.12/protected/vendor/codeception/codeception/tests/data/app/view/index.php
HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/73.0.3683.83 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Enc
No writeups or analysis indexed.
2020-01-17
Published