Search Options

Results per page
Sort
Preferred Languages
Advance

Results 1 - 10 of 29 for vulnerabilities (0.06 sec)

  1. .github/workflows/codeql-analysis.yml

            # Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python']
            language: ['java']
            # Learn more...
            # https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#overriding-automatic-language-detection
    
        steps:
        - name: Checkout repository
          uses: actions/checkout@v4
    
        # Initializes the CodeQL tools for scanning.
    Registered: Sat Dec 20 09:13:53 UTC 2025
    - Last Modified: Thu Nov 20 13:34:13 UTC 2025
    - 2.1K bytes
    - Viewed (0)
  2. src/main/java/org/codelibs/fess/crawler/serializer/DataSerializer.java

                // TODO use kryo.register for security
                // SECURITY WARNING: setRegistrationRequired(false) allows deserialization of arbitrary classes
                // which could potentially lead to remote code execution vulnerabilities.
                // This should be replaced with explicit class registration using kryo.register()
                // for all classes that need to be serialized/deserialized.
                kryo.setRegistrationRequired(false);
    Registered: Sat Dec 20 09:19:18 UTC 2025
    - Last Modified: Wed Nov 19 07:09:17 UTC 2025
    - 6.5K bytes
    - Viewed (3)
  3. src/main/java/org/codelibs/fess/ds/DataStoreFactory.java

         * in the data store plugin directory and extracts component class names.
         *
         * <p>The method uses secure XML parsing features to prevent XXE attacks and
         * other XML-based vulnerabilities. Component class names are extracted from
         * the 'class' attribute of 'component' elements in the XML files.</p>
         *
         * @return sorted list of data store class simple names discovered from plugins
         */
    Registered: Sat Dec 20 09:19:18 UTC 2025
    - Last Modified: Fri Nov 28 16:29:12 UTC 2025
    - 9K bytes
    - Viewed (0)
  4. src/main/java/jcifs/util/InputValidator.java

    import java.util.regex.Pattern;
    
    /**
     * Comprehensive input validation utility for SMB protocol implementation.
     * Provides validation methods to prevent buffer overflows, injection attacks,
     * and other security vulnerabilities.
     */
    public final class InputValidator {
    
        private InputValidator() {
            // Utility class
        }
    
        // Maximum sizes for various SMB fields (based on protocol specifications)
    Registered: Sat Dec 20 13:44:44 UTC 2025
    - Last Modified: Sat Aug 30 05:58:03 UTC 2025
    - 13.5K bytes
    - Viewed (0)
  5. src/main/java/org/codelibs/core/io/SerializeUtil.java

         * <p>
         * WARNING: Use this only when you completely trust the data source and have
         * other security measures in place. Unrestricted deserialization can lead to
         * remote code execution vulnerabilities.
         * </p>
         *
         * @return an ObjectInputFilter that allows all classes
         */
        public static ObjectInputFilter createPermissiveFilter() {
    Registered: Sat Dec 20 08:55:33 UTC 2025
    - Last Modified: Sat Nov 22 11:21:59 UTC 2025
    - 9K bytes
    - Viewed (0)
  6. android/guava/src/com/google/common/io/Files.java

       * delete the file and create a directory in its place, but this leads a race condition which can
       * be exploited to create security vulnerabilities, especially when executable files are to be
       * written into the directory.
       *
       * <p>This method assumes that the temporary volume is writable, has free inodes and free blocks,
    Registered: Fri Dec 26 12:43:10 UTC 2025
    - Last Modified: Thu Sep 25 20:24:13 UTC 2025
    - 32.8K bytes
    - Viewed (0)
  7. guava/src/com/google/common/io/Files.java

       * delete the file and create a directory in its place, but this leads a race condition which can
       * be exploited to create security vulnerabilities, especially when executable files are to be
       * written into the directory.
       *
       * <p>This method assumes that the temporary volume is writable, has free inodes and free blocks,
    Registered: Fri Dec 26 12:43:10 UTC 2025
    - Last Modified: Thu Sep 25 20:24:13 UTC 2025
    - 32.8K bytes
    - Viewed (0)
  8. CHANGELOG/CHANGELOG-1.27.md

    ## Changelog since v1.27.15
    
    ## Important Security Information
    
    This release contains changes that address the following vulnerabilities:
    
    ### CVE-2024-5321: Incorrect permissions on Windows containers logs
    
    A security issue was discovered in Kubernetes clusters with Windows nodes
    where BUILTIN\Users may be able to read container logs and NT
    Registered: Fri Dec 26 09:05:12 UTC 2025
    - Last Modified: Wed Jul 17 07:48:22 UTC 2024
    - 466.3K bytes
    - Viewed (2)
  9. CHANGELOG/CHANGELOG-1.29.md

    ## Changelog since v1.29.12
    
    ## Important Security Information
    
    This release contains changes that address the following vulnerabilities:
    
    ### CVE-2024-9042: Command Injection affecting Windows nodes via nodes/*/logs/query API
    
    A security vulnerability has been discovered in Kubernetes windows nodes
    Registered: Fri Dec 26 09:05:12 UTC 2025
    - Last Modified: Wed Mar 12 00:36:01 UTC 2025
    - 429.6K bytes
    - Viewed (1)
  10. src/main/java/org/codelibs/fess/ldap/LdapManager.java

         * </ul>
         *
         * <p><strong>Security Note:</strong> This method MUST be called on all user-supplied
         * input before using it in LDAP search filters to prevent LDAP injection vulnerabilities.
         *
         * @param filter the LDAP search filter to escape (null is treated as empty string)
         * @return the escaped filter string safe for use in LDAP queries (empty string if filter is null)
    Registered: Sat Dec 20 09:19:18 UTC 2025
    - Last Modified: Fri Nov 28 16:29:12 UTC 2025
    - 86.3K bytes
    - Viewed (0)
Back to top