Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-34491PUBLISHED: 2022-06-25
In the RSS extension for MediaWiki through 1.38.1, when the $wgRSSAllowLinkTag config variable was set to true, and a new RSS feed was created with certain XSS payloads within its description tags and added to the $wgRSSUrlWhitelist config variable, stored XSS could occur via MediaWiki's template sy...
CVE-2022-29931PUBLISHED: 2022-06-25Raytion 7.2.0 allows reflected Cross-site Scripting (XSS).
CVE-2022-31017PUBLISHED: 2022-06-25
Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic error. A stream configured as private with protected history, where new subscribers should not be allowed to see messages sent before they were subscribed, when edited causes the serve...
CVE-2022-31016PUBLISHED: 2022-06-25
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized malicious user to crash the repo-server service, resulting in a Denial of Service. The attacker must be an authenticated A...
CVE-2022-24893PUBLISHED: 2022-06-25
ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can resul...
User Rank: Strategist
10/29/2020 | 2:01:50 PM
Unfortunately, many cyber insurance policies contain other layers of obnoxious surprises. Arbitration provisions, my area of expertise, and inclusion of "foreign" law are but a few of the many other devices also used by some insurance companies.
Large companies can, and should negotiate EVERY component of coverage and EVERY endorsement excluding or limiting coverage.
Smaller companies must rely on astute policyholder only insurance coverage attorneys. Insurance brokers are important, but all purchasers have to remember that "their" insurance brokers must always maintain and preserve their relationships with the insurance companies to stay in business. Policyholder only insurance coverage attorneys can not, and do not, have those divided loyalties.
It all can be summarized as "RFP." Read the Fine Print & Read the Full Policy!!
Buyers beware!!!!