Tags: SJTU-Geek/Aixinwu-core
Tags
- async webhooks: add extra data in failure logs - CVE fixes: * (cryptography) CVE-2023-49083: NULL-dereference when loading PKCS7 certificates. * (pillow) CVE-2023-50447: Arbitrary Code Execution in Pillow. * (pillow) No CVE: ImageFont.getmask: (2x) potential DoS. * (jinja2) CVE-2024-22195: vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter.
- async webhooks: add extra data in failure logs - CVE fixes: * (cryptography) CVE-2023-49083: NULL-dereference when loading PKCS7 certificates. * (pillow) CVE-2023-50447: Arbitrary Code Execution in Pillow. * (pillow) No CVE: ImageFont.getmask: (2x) potential DoS. * (jinja2) CVE-2024-22195: vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter.
- async webhooks: add extra data in failure logs - CVE fixes: * (cryptography) CVE-2023-49083: NULL-dereference when loading PKCS7 certificates. * (pillow) CVE-2023-50447: Arbitrary Code Execution in Pillow. * (pillow) No CVE: ImageFont.getmask: (2x) potential DoS. * (jinja2) CVE-2024-22195: vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter.
- async webhooks: add extra data in failure logs - CVE fixes: * (cryptography) CVE-2023-49083: NULL-dereference when loading PKCS7 certificates. * (pillow) CVE-2023-50447: Arbitrary Code Execution in Pillow. * (pillow) No CVE: ImageFont.getmask: (2x) potential DoS. * (jinja2) CVE-2024-22195: vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter.
PreviousNext