A vulnerability classified as problematic has been found in IPFire 2.21. Affected is an unknown code block of the component Captive Portal. Upgrading to version 2.23 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at blog.ipfire.org. The best possible mitigation is suggested to be upgrading to the latest version.
IPFire 2.21 Captive Portal Title of Login Page/TITLE cross site scripting
- Virtual Patching
- June 17, 2021
- 7:04 pm
CVE-2023-4291 : Frauscher Sensortechnik FDS101 For FAdC 1.4.24 Code Injection
Description Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE)
CVE-2023-2163 : Linux Kernel 5.4 BPF kernel/bpf/verifier.c backtrack_insn calculation
Description Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe,
CVE-2023-42454 : SQLpage Up To 0.11.0 Database Connection String sqlpage/sqlpage.json Information Disclosure
Description SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly,