CVE-2020-1454
published 2020-07-14CVE-2020-1454: This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated…
PriorityP431medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.57%
72.7th percentile
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_msrc5.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Reflective XSS Vulnerability
vendor_msrc·2020-07-14·CVSS 5.4
CVE-2020-1454 [MEDIUM] Microsoft SharePoint Reflective XSS Vulnerability
Microsoft SharePoint Reflective XSS Vulnerability
Description: This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.
An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. These attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the victim, such as change permissions, delete content, steal sensitive information (such as brows
GHSA
GHSA-5v5r-fxmr-wmpv: This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server
ghsa_unreviewed·2022-05-24
CVE-2020-1454 [LOW] CWE-79 GHSA-5v5r-fxmr-wmpv: This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10716 rubygem-foreman_ansible: "User input" entry from Job Invocation may contain sensitive data
bugzilla·2020-04-23·CVSS 6.5
CVE-2020-10716 [MEDIUM] CVE-2020-10716 rubygem-foreman_ansible: "User input" entry from Job Invocation may contain sensitive data
CVE-2020-10716 rubygem-foreman_ansible: "User input" entry from Job Invocation may contain sensitive data
The "User input" entry from Job Invocation may contain plaintext password or other sensitive data. As a result, anyone who could view the job invocation could see it.
The fix was to restrict the ability to view Job Invocation to users to are entitle to execute it.
Discussion:
Acknowledgments:
Name: Lukáš Hellebrandt (Red Hat)
---
This was fixed via the following errata :
https://access.redhat.com/errata/RHSA-2020:1454
---
External References:
https://bugzilla.redhat.com/show_bug.cgi?id=1814998
Bugzilla
CVE-2019-7397 ImageMagick: Memory leak in the WritePDFImage function in coders/pdf.c
bugzilla·2019-02-05·CVSS 7.5
CVE-2019-7397 [HIGH] CVE-2019-7397 ImageMagick: Memory leak in the WritePDFImage function in coders/pdf.c
CVE-2019-7397 ImageMagick: Memory leak in the WritePDFImage function in coders/pdf.c
In ImageMagick before 7.0.8-25, several memory leaks exist in WritePDFImage in coders/pdf.c.
References:
https://github.com/ImageMagick/ImageMagick/commit/306c1f0fa5754ca78efd16ab752f0e981d4f6b82
https://github.com/ImageMagick/ImageMagick/issues/1454
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1672590]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/306c1f0fa5754ca78efd16ab752f0e981d4f6b82
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/3b28c8d93aa469f6d90c8b3c05fe3d88c2584e32
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redh
2020-07-14
Published