<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from github</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:48:47 +0000</lastBuildDate>
    <item>
      <title>GHSA-89ch-hqf9-rgp3 — Using JS libraries with known security vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-89ch-hqf9-rgp3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: magento/community-edition, Packagist: magento/product-community-edition&lt;/p&gt;
&lt;p&gt;An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: magento/community-edition, Packagist: magento/product-community-edition&lt;/p&gt;
&lt;p&gt;An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-89ch-hqf9-rgp3</guid>
      <pubDate>Tue, 12 Nov 2019 22:59:28 +0000</pubDate>
    </item>
    <item>
      <title>Withdrawn: GHSA-6r5x-hmgg-7h53 — Remote code execution in Handlebars.js</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6r5x-hmgg-7h53</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: handlebars&lt;/p&gt;
&lt;p&gt;Handlebars.js before 4.1.0 has Remote Code Execution (RCE)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: handlebars&lt;/p&gt;
&lt;p&gt;Handlebars.js before 4.1.0 has Remote Code Execution (RCE)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6r5x-hmgg-7h53</guid>
      <pubDate>Mon, 15 Jul 2019 19:46:01 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-m5ff-3wj3-8ph4 — HTTP Request Smuggling: Invalid whitespace characters in headers in Waitress</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m5ff-3wj3-8ph4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: waitress&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling.&lt;/p&gt;
&lt;p&gt;```
Content-Length: 10
Transfer-Encoding: [\x0b]chunked
```&lt;/p&gt;
&lt;p&gt;For clarity:&lt;/p&gt;
&lt;p&gt;```
0x0b == vertical tab
```&lt;/p&gt;
&lt;p&gt;Would get parsed by Waitress as being a `chunked` request, but a front-end server would use the `Content-Length` instead as the `Transfer-Encoding` header is considered invalid due to containing invalid characters.&lt;/p&gt;
&lt;p&gt;If a front-end server does HTTP pipelining to a backend Waitress server this could lead to HTTP request splitting which may lead to potential cache poisoning or unexpected information disclosure.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Please upgrade to Waitress 1.4.1 which fixes this issue with stricter HTTP field validation.&lt;/p&gt;
&lt;p&gt;Waitress 1.4.1 due to this change has become much more strict in what is allowed in header values, while the maintainers don&amp;#39;t believe that these changes will cause any issues, it may cause failures with non-conformist reverse proxies or clients, and it is highly recommend that users validate the changes in their environment and make sure it won&amp;#39;t cause any unacceptable failures.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;You may enable additional protections on front-end servers, those that follow RFC7230 correctly would drop the request with a 400 Bad Request.&lt;/p&gt;
&lt;p&gt;Waitress will now correctly responds to the request with a 400 Bad Request, and will drop the connection…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: waitress&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling.&lt;/p&gt;
&lt;p&gt;```
Content-Length: 10
Transfer-Encoding: [\x0b]chunked
```&lt;/p&gt;
&lt;p&gt;For clarity:&lt;/p&gt;
&lt;p&gt;```
0x0b == vertical tab
```&lt;/p&gt;
&lt;p&gt;Would get parsed by Waitress as being a `chunked` request, but a front-end server would use the `Content-Length` instead as the `Transfer-Encoding` header is considered invalid due to containing invalid characters.&lt;/p&gt;
&lt;p&gt;If a front-end server does HTTP pipelining to a backend Waitress server this could lead to HTTP request splitting which may lead to potential cache poisoning or unexpected information disclosure.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Please upgrade to Waitress 1.4.1 which fixes this issue with stricter HTTP field validation.&lt;/p&gt;
&lt;p&gt;Waitress 1.4.1 due to this change has become much more strict in what is allowed in header values, while the maintainers don&amp;#39;t believe that these changes will cause any issues, it may cause failures with non-conformist reverse proxies or clients, and it is highly recommend that users validate the changes in their environment and make sure it won&amp;#39;t cause any unacceptable failures.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;You may enable additional protections on front-end servers, those that follow RFC7230 correctly would drop the request with a 400 Bad Request.&lt;/p&gt;
&lt;p&gt;Waitress will now correctly responds to the request with a 400 Bad Request, and will drop the connection…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m5ff-3wj3-8ph4</guid>
      <pubDate>Thu, 26 Dec 2019 16:34:38 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-f884-gm86-cg3q — PrestaShop module ps_facetedsearch might be vulnerable from CVE-2017-9841</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f884-gm86-cg3q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: prestashop/ps_facetedsearch&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;We have identified that some ps_facetedsearch module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.&lt;/p&gt;
&lt;p&gt;This vulnerability impacts
- phpunit before 4.8.28 and 5.x before 5.6.3 as reported in [CVE-2017-9841](https://nvd.nist.gov/vuln/detail/CVE-2017-9841)
- phpunit &amp;gt;= 5.63 before 7.5.19 and 8.5.1 (this is a newly found vulnerability that is currently being submitted as a CVE after disclosure was provided to phpunit maintainers)&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;In the [security patch](https://github.com/PrestaShop/ps_facetedsearch/releases/tag/v3.4.1), we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.&lt;/p&gt;
&lt;p&gt;### Workarounds
Users can also simply remove the unwanted vendor/phpunit folder.&lt;/p&gt;
&lt;p&gt;### References
https://nvd.nist.gov/vuln/detail/CVE-2017-9841&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, email us at security@prestashop.com&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: prestashop/ps_facetedsearch&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;We have identified that some ps_facetedsearch module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.&lt;/p&gt;
&lt;p&gt;This vulnerability impacts
- phpunit before 4.8.28 and 5.x before 5.6.3 as reported in [CVE-2017-9841](https://nvd.nist.gov/vuln/detail/CVE-2017-9841)
- phpunit &amp;gt;= 5.63 before 7.5.19 and 8.5.1 (this is a newly found vulnerability that is currently being submitted as a CVE after disclosure was provided to phpunit maintainers)&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;In the [security patch](https://github.com/PrestaShop/ps_facetedsearch/releases/tag/v3.4.1), we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.&lt;/p&gt;
&lt;p&gt;### Workarounds
Users can also simply remove the unwanted vendor/phpunit folder.&lt;/p&gt;
&lt;p&gt;### References
https://nvd.nist.gov/vuln/detail/CVE-2017-9841&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, email us at security@prestashop.com&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f884-gm86-cg3q</guid>
      <pubDate>Tue, 07 Jan 2020 17:20:47 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-wqq8-mqj9-697f — PrestaShop autoupgrade module ZIP archives were vulnerable from CVE-2017-9841</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wqq8-mqj9-697f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: prestashop/autoupgrade&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;We have identified that some autoupgrade module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.&lt;/p&gt;
&lt;p&gt;This vulnerability impacts
- phpunit before 4.8.28 and 5.x before 5.6.3 as reported in [CVE-2017-9841](https://nvd.nist.gov/vuln/detail/CVE-2017-9841)
- phpunit &amp;gt;= 5.63 before 7.5.19 and 8.5.1 (this is a newly found vulnerability that is currently being submitted as a CVE after disclosure was provided to phpunit maintainers)&lt;/p&gt;
&lt;p&gt;You can read PrestaShop official statement about this vulnerability [here](https://build.prestashop.com/news/critical-security-vulnerability-in-prestashop-modules/).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;In the [security patch](https://github.com/PrestaShop/autoupgrade/releases/tag/v4.10.1), we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.&lt;/p&gt;
&lt;p&gt;### Workarounds
Users can also simply remove the unwanted vendor/phpunit folder.&lt;/p&gt;
&lt;p&gt;### References
https://nvd.nist.gov/vuln/detail/CVE-2017-9841&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, email us at security@prestashop.com&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: prestashop/autoupgrade&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;We have identified that some autoupgrade module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.&lt;/p&gt;
&lt;p&gt;This vulnerability impacts
- phpunit before 4.8.28 and 5.x before 5.6.3 as reported in [CVE-2017-9841](https://nvd.nist.gov/vuln/detail/CVE-2017-9841)
- phpunit &amp;gt;= 5.63 before 7.5.19 and 8.5.1 (this is a newly found vulnerability that is currently being submitted as a CVE after disclosure was provided to phpunit maintainers)&lt;/p&gt;
&lt;p&gt;You can read PrestaShop official statement about this vulnerability [here](https://build.prestashop.com/news/critical-security-vulnerability-in-prestashop-modules/).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;In the [security patch](https://github.com/PrestaShop/autoupgrade/releases/tag/v4.10.1), we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.&lt;/p&gt;
&lt;p&gt;### Workarounds
Users can also simply remove the unwanted vendor/phpunit folder.&lt;/p&gt;
&lt;p&gt;### References
https://nvd.nist.gov/vuln/detail/CVE-2017-9841&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, email us at security@prestashop.com&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wqq8-mqj9-697f</guid>
      <pubDate>Wed, 08 Jan 2020 03:10:30 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-769f-539v-f5jg — PrestaShop gamification module ZIP archives were vulnerable from CVE-2017-9841</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-769f-539v-f5jg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: prestashop/gamification&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;We have identified that some gamification module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.&lt;/p&gt;
&lt;p&gt;This vulnerability impacts
- phpunit before 4.8.28 and 5.x before 5.6.3 as reported in [CVE-2017-9841](https://nvd.nist.gov/vuln/detail/CVE-2017-9841)
- phpunit &amp;gt;= 5.63 before 7.5.19 and 8.5.1 (this is a newly found vulnerability that is currently being submitted as a CVE after disclosure was provided to phpunit maintainers)&lt;/p&gt;
&lt;p&gt;You can read PrestaShop official statement about this vulnerability [here](https://build.prestashop.com/news/critical-security-vulnerability-in-prestashop-modules/).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;In the [security patch](https://github.com/PrestaShop/gamification/releases/tag/v2.3.2), we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.&lt;/p&gt;
&lt;p&gt;### Workarounds
Users can also simply remove the unwanted vendor/phpunit folder.&lt;/p&gt;
&lt;p&gt;### References
https://nvd.nist.gov/vuln/detail/CVE-2017-9841&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, email us at security@prestashop.com&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: prestashop/gamification&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;We have identified that some gamification module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.&lt;/p&gt;
&lt;p&gt;This vulnerability impacts
- phpunit before 4.8.28 and 5.x before 5.6.3 as reported in [CVE-2017-9841](https://nvd.nist.gov/vuln/detail/CVE-2017-9841)
- phpunit &amp;gt;= 5.63 before 7.5.19 and 8.5.1 (this is a newly found vulnerability that is currently being submitted as a CVE after disclosure was provided to phpunit maintainers)&lt;/p&gt;
&lt;p&gt;You can read PrestaShop official statement about this vulnerability [here](https://build.prestashop.com/news/critical-security-vulnerability-in-prestashop-modules/).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;In the [security patch](https://github.com/PrestaShop/gamification/releases/tag/v2.3.2), we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.&lt;/p&gt;
&lt;p&gt;### Workarounds
Users can also simply remove the unwanted vendor/phpunit folder.&lt;/p&gt;
&lt;p&gt;### References
https://nvd.nist.gov/vuln/detail/CVE-2017-9841&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, email us at security@prestashop.com&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-769f-539v-f5jg</guid>
      <pubDate>Wed, 08 Jan 2020 03:10:44 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-9r27-994c-4xch — discord-html not escaping HTML code blocks when lacking a language identifier</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9r27-994c-4xch</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: discord-markdown&lt;/p&gt;
&lt;p&gt;### Impact
Any website using discord-markdown with user-generated markdown is vulnerable to having code injected into the page where the markdown is displayed.&lt;/p&gt;
&lt;p&gt;### Patches
This has been patched in version 2.3.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Escape the characters `&amp;amp;lt;&amp;amp;gt;&amp;amp;amp;` before sending plain code blocks to discord-markdown.&lt;/p&gt;
&lt;p&gt;### References
https://github.com/brussell98/discord-markdown/issues/13&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: discord-markdown&lt;/p&gt;
&lt;p&gt;### Impact
Any website using discord-markdown with user-generated markdown is vulnerable to having code injected into the page where the markdown is displayed.&lt;/p&gt;
&lt;p&gt;### Patches
This has been patched in version 2.3.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Escape the characters `&amp;amp;lt;&amp;amp;gt;&amp;amp;amp;` before sending plain code blocks to discord-markdown.&lt;/p&gt;
&lt;p&gt;### References
https://github.com/brussell98/discord-markdown/issues/13&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9r27-994c-4xch</guid>
      <pubDate>Mon, 24 Feb 2020 17:34:02 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-p94w-42g3-f7h4 — Holder can (re)create authentic credentials after receiving a credential in vp-toolkit</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p94w-42g3-f7h4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vp-toolkit&lt;/p&gt;
&lt;p&gt;### Impact
The [`verifyVerifiableCredential()`](https://github.com/rabobank-blockchain/vp-toolkit/blob/master/src/service/signers/verifiable-credential-signer.ts#L57) method check the cryptographic integrity of the Verifiable Credential, but it does not check if the [`credential.issuer`](https://github.com/rabobank-blockchain/vp-toolkit-models/blob/develop/src/model/verifiable-credential.ts#L129) DID matches the signer of the credential.&lt;/p&gt;
&lt;p&gt;The **verifier** is impacted by this vulnerability.&lt;/p&gt;
&lt;p&gt;### Patches
Patch will be available in version 0.2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds
In case you trust certain issuers for certain credentials as a verifier, trust the issuer&amp;amp;#39;s public key from the `credential.proof.verificationMethod` field.&lt;/p&gt;
&lt;p&gt;### References
[Github issue](https://github.com/rabobank-blockchain/vp-toolkit/issues/13)&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Discuss in the existing [issue](https://github.com/rabobank-blockchain/vp-toolkit/issues/13)
* [Contact me](https://github.com/rabomarnix)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vp-toolkit&lt;/p&gt;
&lt;p&gt;### Impact
The [`verifyVerifiableCredential()`](https://github.com/rabobank-blockchain/vp-toolkit/blob/master/src/service/signers/verifiable-credential-signer.ts#L57) method check the cryptographic integrity of the Verifiable Credential, but it does not check if the [`credential.issuer`](https://github.com/rabobank-blockchain/vp-toolkit-models/blob/develop/src/model/verifiable-credential.ts#L129) DID matches the signer of the credential.&lt;/p&gt;
&lt;p&gt;The **verifier** is impacted by this vulnerability.&lt;/p&gt;
&lt;p&gt;### Patches
Patch will be available in version 0.2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds
In case you trust certain issuers for certain credentials as a verifier, trust the issuer&amp;amp;#39;s public key from the `credential.proof.verificationMethod` field.&lt;/p&gt;
&lt;p&gt;### References
[Github issue](https://github.com/rabobank-blockchain/vp-toolkit/issues/13)&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Discuss in the existing [issue](https://github.com/rabobank-blockchain/vp-toolkit/issues/13)
* [Contact me](https://github.com/rabomarnix)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p94w-42g3-f7h4</guid>
      <pubDate>Fri, 06 Mar 2020 01:16:00 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-ff5x-w9wg-h275 — Holder can generate proof of ownership for credentials it does not control in vp-toolkit</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ff5x-w9wg-h275</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vp-toolkit&lt;/p&gt;
&lt;p&gt;### Impact
The [`verifyVerifiablePresentation()`](https://github.com/rabobank-blockchain/vp-toolkit/blob/master/src/service/signers/verifiable-presentation-signer.ts#L97) method check the cryptographic integrity of the Verifiable Presentation, but it does not check if the [`credentialSubject.id`](https://github.com/rabobank-blockchain/vp-toolkit-models/blob/develop/src/model/verifiable-credential.ts#L150) DID matches the signer of the VP proof.&lt;/p&gt;
&lt;p&gt;The **verifier** is impacted by this vulnerability.&lt;/p&gt;
&lt;p&gt;### Patches
Patch will be available in version 0.2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds
- Compute the address out of the `verifiablePresentation.proof.n.verificationMethod` using `getAddressFromPubKey()` from `crypt-util@0.1.5` and match it with the `credentialSubject.id` address from the credential.&lt;/p&gt;
&lt;p&gt;### References
[Github issue](https://github.com/rabobank-blockchain/vp-toolkit/issues/14)&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Discuss in the existing [issue](https://github.com/rabobank-blockchain/vp-toolkit/issues/14)
* [Contact me](https://github.com/rabomarnix)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vp-toolkit&lt;/p&gt;
&lt;p&gt;### Impact
The [`verifyVerifiablePresentation()`](https://github.com/rabobank-blockchain/vp-toolkit/blob/master/src/service/signers/verifiable-presentation-signer.ts#L97) method check the cryptographic integrity of the Verifiable Presentation, but it does not check if the [`credentialSubject.id`](https://github.com/rabobank-blockchain/vp-toolkit-models/blob/develop/src/model/verifiable-credential.ts#L150) DID matches the signer of the VP proof.&lt;/p&gt;
&lt;p&gt;The **verifier** is impacted by this vulnerability.&lt;/p&gt;
&lt;p&gt;### Patches
Patch will be available in version 0.2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds
- Compute the address out of the `verifiablePresentation.proof.n.verificationMethod` using `getAddressFromPubKey()` from `crypt-util@0.1.5` and match it with the `credentialSubject.id` address from the credential.&lt;/p&gt;
&lt;p&gt;### References
[Github issue](https://github.com/rabobank-blockchain/vp-toolkit/issues/14)&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Discuss in the existing [issue](https://github.com/rabobank-blockchain/vp-toolkit/issues/14)
* [Contact me](https://github.com/rabomarnix)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ff5x-w9wg-h275</guid>
      <pubDate>Fri, 06 Mar 2020 01:15:46 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-738m-f33v-qc2r — SMTP Injection in PHPMailer</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-738m-f33v-qc2r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: phpmailer/phpmailer&lt;/p&gt;
&lt;p&gt;### Impact
Attackers could inject arbitrary SMTP commands via by exploiting the fact that valid email addresses may contain line breaks, which are not handled correctly in some contexts.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in 5.2.14 in [this commit](https://github.com/PHPMailer/PHPMailer/commit/6687a96a18b8f12148881e4ddde795ae477284b0).&lt;/p&gt;
&lt;p&gt;### Workarounds
Manually strip line breaks from email addresses before passing them to PHPMailer.&lt;/p&gt;
&lt;p&gt;### References
https://nvd.nist.gov/vuln/detail/CVE-2015-8476&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open a private issue in [the PHPMailer project](https://github.com/PHPMailer/PHPMailer)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: phpmailer/phpmailer&lt;/p&gt;
&lt;p&gt;### Impact
Attackers could inject arbitrary SMTP commands via by exploiting the fact that valid email addresses may contain line breaks, which are not handled correctly in some contexts.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in 5.2.14 in [this commit](https://github.com/PHPMailer/PHPMailer/commit/6687a96a18b8f12148881e4ddde795ae477284b0).&lt;/p&gt;
&lt;p&gt;### Workarounds
Manually strip line breaks from email addresses before passing them to PHPMailer.&lt;/p&gt;
&lt;p&gt;### References
https://nvd.nist.gov/vuln/detail/CVE-2015-8476&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open a private issue in [the PHPMailer project](https://github.com/PHPMailer/PHPMailer)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-738m-f33v-qc2r</guid>
      <pubDate>Thu, 05 Mar 2020 22:09:19 +0000</pubDate>
    </item>
  </channel>
</rss>
