[oss-security] CVE-2025-43023 in HPLIP for Use of 1024-bit DSA Key

2025-08-22 Thread Alan Coopersmith
CVE-2025-43023 is a bit of an odd vulnerability. https://support.hp.com/us-en/document/ish_12804224-12804228-16/hpsbpi04033 says: HP Linux Imaging and Printing Software - Use of DSA Key A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software do

[oss-security] CVE-2025-54813: Apache Log4cxx: Improper escaping with JSONLayout

2025-08-22 Thread Piotr Karwasz
Severity: moderate Affected versions: - Apache Log4cxx 0.11.0 before 1.5.0 Description: Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable c

[oss-security] CVE-2025-54812: Apache Log4cxx: Improper HTML escaping in HTMLLayout

2025-08-22 Thread Piotr Karwasz
Severity: low Affected versions: - Apache Log4cxx before 1.5.0 Description: Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. If untrusted data is used to retrieve the name

[oss-security] CVE-2024-48988: Apache StreamPark: SQL injection vulnerability

2025-08-22 Thread Huajie Wang
Severity: low Affected versions: - Apache StreamPark 2.1.4 before 2.1.6 Description: SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability