writeups.xyz writeups.xyz / Justin Steven (@Justinsteven)

Title Vulnerabilities Programs Authors
postMessage DOM XSS vulnerability in Gartner Peer Insights widget
Amazon Linux "log4j hotpatch" <1.3-5 local privilege escalation to root (race condition)
Git honours embedded bare repos, and exploitation via core.fsmonitor in a directory's .git/config affects IDEs, shell prompts and Git pillagers
GitHub Actions check-spelling community workflow - GITHUB_TOKEN leakage via advice.txt symlink
OVE-20210809-0001 Visual Studio Code .ipynb Jupyter Notebook XSS (Arbitrary File Read)