Draft in the CWE catalog · 6 CVEs mapped
The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.
⚡ So close to a magical platform, but a sneaky iframe could let bad JavaScript slip right in! Before you know it, Codepen could run code you didn't intend it to. 🔥 Think of Discourse as a cozy café where the barista serves up delicious conversations. However, leaving an open window could let in a mischievous raccoon who tosses around unwanted ingredients in the café's recipes! If exploited, attackers could inject and execute any JavaScript within the iframe, potentially compromising user session data, altering content, or even redirecting users elsewhere - chaos in your cozy café! This vulnerability could lead to a serious breach of trust on your platform.
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2.
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.