
Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.
Twitter: @justinsteven
Blog: https://www.justinsteven.com/
Listed in reverse chronological order. Click any title to read the full advisory.
log4j-cve-2021-44228-hotpatch-1.1.16, were vulnerable to local privilege escalation via race condition. The vulnerable version would unsafely observe the EUID and EGID of a process before executing its underlying binary allowing local privilege escalation to root.core.fsmonitor can be shown to be dangerous. Software such as IDEs, shell prompt decorations and Git repo pillaging tools can be shown to be vulnerable to various impacts including remote code execution and/or arbitrary file write.check-spelling GitHub actions community workflow can be made to leak a GITHUB_TOKEN short-lived API key within a Pull Request comment by sending a Pull Request containing a symlink called .github/actions/advice.txt which points to /proc/self/environ.msfvenom payload generator, when given a crafted APK file to use as a payload template, were vulnerable to a command injection vulnerability in the handling of the crafted APK file.fwupd uses LVFS to obtain firmware metadata for performing firmware updates on Linux systems. A legacy LVFS S3 bucket was available for registration, and a signature verification bypass in fwupd was discovered which could have allowed an attacker to offer malicious firmware updates to ~100,000 Linux machines.python.pythonPath value.rbenv use the contents of the .ruby-version file within a directory, or within any directory up to the root, to determine the Ruby interpreter to use. Furthermore, the .ruby-version file may contain path traversal sequences, allowing the specification of an arbitrary binary on the local filesystem. In some situations this can result in arbitrary code execution or local privilege escalation.git.path value.cd to swich into a directory containing malicious files.