2025年11月13日星期四

GitLab 多個漏洞

GitLab 多個漏洞

發佈日期: 2025年11月13日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、權限提升、阻斷服務、洩露敏感資料及繞過保安限制。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露
  • 權限提升
  • 跨網站指令碼

受影響之系統或技術

  • GitLab Community Edition (CE) 18.5.2, 18.4.4, 18.3.6 以前的版本
  • GitLab Enterprise Edition (EE) 18.5.2, 18.4.4, 18.3.6 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

GitLab Multiple Vulnerabilities

Release Date: 13 Nov 2025

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, elevation of privilege, denial of service condition, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure
  • Elevation of Privilege
  • Cross-Site Scripting

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 18.5.2, 18.4.4, 18.3.6
  • GitLab Enterprise Edition (EE) versions prior to 18.5.2, 18.4.4, 18.3.6

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Mozilla Firefox 多個漏洞

Mozilla Firefox 多個漏洞

發佈日期: 2025年11月13日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla Firefox 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、彷冒、遠端執行任意程式碼及繞過保安限制。

 

影響

  • 阻斷服務
  • 遠端執行程式碼
  • 仿冒
  • 繞過保安限制

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox ESR 115.30
  • Firefox ESR 140.5
  • Firefox 145

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox ESR 115.30
  • Firefox ESR 140.5
  • Firefox 145
 

漏洞識別碼


資料來源


相關連結

Mozilla Firefox Multiple Vulnerabilities

Mozilla Firefox Multiple Vulnerabilities

Release Date: 13 Nov 2025

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Firefox. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, remote code execution and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Spoofing
  • Security Restriction Bypass

System / Technologies affected

Versions prior to:

 

  • Firefox ESR 115.30
  • Firefox ESR 140.5
  • Firefox 145
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox ESR 115.30
  • Firefox ESR 140.5
  • Firefox 145

Vulnerability Identifier


Source


Related Link

Palo Alto PAN-OS 阻斷服務狀況漏洞

Palo Alto PAN-OS 阻斷服務狀況漏洞

發佈日期: 2025年11月13日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

在 Palo Alto PAN-OS 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • PAN-OS 10.2 版本 >= 10.2.4-h25, >= 10.2.7-h11, < 10.2.7-h24, >= 10.2.8-h10, < 10.2.8-h21, >= 10.2.9-h6, < 10.2.9-h21, >= 10.2.10-h2, < 10.2.10-h14, < 10.2.11-h12,< 10.2.12-h6, < 10.2.13-h3, < 10.2.14 >= 10.2.8, < 10.2.14
  • PAN-OS 11.1 版本 >= 11.1.2-h9, < 11.1.2-h18, >= 11.1.3-h2, >= 11.1.4-h4, < 11.1.4-h13, < 11.1.6-h1, < 11.1.7
  • PAN-OS 11.2 版本 < 11.2.2-h2, < 11.2.3-h6, < 11.2.4-h4, < 11.2.5
  • PAN-OS Prisma Access 版本  >= 10.2.4-h25, < 10.2.10-h14, < 11.2.4-h4

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Palo Alto PAN-OS Denial Of Service Vulnerability

Palo Alto PAN-OS Denial Of Service Vulnerability

Release Date: 13 Nov 2025

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

A vulnerability was identified in Palo Alto PAN-OS. A remote attacker can exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • PAN-OS 10.2 versions >= 10.2.4-h25, >= 10.2.7-h11, < 10.2.7-h24, >= 10.2.8-h10, < 10.2.8-h21, >= 10.2.9-h6, < 10.2.9-h21, >= 10.2.10-h2, < 10.2.10-h14, < 10.2.11-h12,< 10.2.12-h6, < 10.2.13-h3, < 10.2.14
  • PAN-OS 11.1 versions >= 11.1.2-h9, < 11.1.2-h18, >= 11.1.3-h2, >= 11.1.4-h4, < 11.1.4-h13, < 11.1.6-h1, < 11.1.7
  • PAN-OS 11.2 versions < 11.2.2-h2, < 11.2.3-h6, < 11.2.4-h4, < 11.2.5
  • PAN-OS Prisma Access versions >= 10.2.4-h25, < 10.2.10-h14, < 11.2.4-h4

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2025年11月12日星期三

Adobe 每月保安更新 (2025年11月)

Adobe 每月保安更新 (2025年11月)

發佈日期: 2025年11月12日

風險: 中度風險

類型: 用戶端 - 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe InDesign中度風險 中度風險遠端執行程式碼 APSB25-106
Adobe InCopy中度風險 中度風險遠端執行程式碼 APSB25-107
Adobe Illustrator中度風險 中度風險遠端執行程式碼 APSB25-109
Adobe Illustrator on iPad中度風險 中度風險遠端執行程式碼 APSB25-111
Adobe Pass中度風險 中度風險繞過保安限制 APSB25-112
Substance 3D Stager中度風險 中度風險遠端執行程式碼 APSB25-113
Adobe Format Plugins中度風險 中度風險遠端執行程式碼
資料洩露
 APSB25-114
Adobe Photoshop中度風險 中度風險遠端執行程式碼 APSB25-108

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:8

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • Adobe InDesign ID20.5 及以前版本
  • Adobe InDesign ID19.5.5 及以前版本
  • Adobe InCopy  20.5 及以前版本
  • Adobe InCopy  19.5.5 及以前版本
  • Illustrator 2025 29.8.2 及以前版本
  • Illustrator 2024 28.7.10 及以前版本
  • Adobe Illustrator on iPad 3.0.9 及以前版本
  • Adobe Pass Authentication Android SDK 3.7.3 及以前版本
  • Adobe Substance 3D Stager 3.1.5 及以前版本
  • Adobe Format Plugins 1.1.1 及以前版本
  • Photoshop 2025 26.8.1 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (November 2025)

Adobe Monthly Security Update (November 2025)

Release Date: 12 Nov 2025

RISK: Medium Risk

TYPE: Clients - Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe InDesignMedium Risk Medium RiskRemote Code Execution APSB25-106
Adobe InCopyMedium Risk Medium RiskRemote Code Execution APSB25-107
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution APSB25-109
Adobe Illustrator on iPadMedium Risk Medium RiskRemote Code Execution APSB25-111
Adobe PassMedium Risk Medium RiskSecurity Restriction Bypass APSB25-112
Substance 3D StagerMedium Risk Medium RiskRemote Code Execution APSB25-113
Adobe Format PluginsMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB25-114
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution APSB25-108

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 8

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Adobe InDesign ID20.5 and earlier versions
  • Adobe InDesign ID19.5.5 and earlier versions
  • Adobe InCopy  20.5 and earlier versions
  • Adobe InCopy  19.5.5 and earlier versions
  • Illustrator 2025 29.8.2 and earlier versions
  • Illustrator 2024 28.7.10 and earlier versions
  • Adobe Illustrator on iPad 3.0.9 and earlier versions
  • Adobe Pass Authentication Android SDK 3.7.3 and earlier versions
  • Adobe Substance 3D Stager 3.1.5 and earlier versions
  • Adobe Format Plugins 1.1.1 and earlier versions
  • Photoshop 2025 26.8.1 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

GitHub Enterprise Server 多個漏洞

GitHub Enterprise Server 多個漏洞

發佈日期: 2025年11月12日

風險: 高度風險

類型: 伺服器 - 其他伺服器

於 GitHub Enterprise Server 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼及跨網站指令碼。

 

注意:

CVE-2025-49844 的概念驗證碼已被公開。經過驗證的使用者可以使用特製的 Lua 腳本來操縱垃圾回收器(garbage collector),觸發 UAF 並可能觸發遠端執行任意程式碼。因此,風險等級被評為高度風險。


影響

  • 遠端執行程式碼
  • 權限提升
  • 跨網站指令碼

受影響之系統或技術

  • GitHub Enterprise Server 3.18.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • 更新至 GitHub Enterprise Server 3.18.1 版本

漏洞識別碼


資料來源


相關連結

GitHub Enterprise Server Multiple Vulnerabilities

GitHub Enterprise Server Multiple Vulnerabilities

Release Date: 12 Nov 2025

RISK: High Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitHub Enterprise Server. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution and cross-site scripting on the targeted system.

 

Note:


Impact

  • Remote Code Execution
  • Elevation of Privilege
  • Cross-Site Scripting

System / Technologies affected

  • GitHub Enterprise Server versions prior to 3.18.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Update to GitHub Enterprise Server versions 3.18.1

Vulnerability Identifier


Source


Related Link

Google Chrome 遠端執行程式碼漏洞

Google Chrome 遠端執行程式碼漏洞

發佈日期: 2025年11月12日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 142.0.7444.162 (Linux) 之前的版本
  • Google Chrome 142.0.7444.162 (Mac) 之前的版本
  • Google Chrome 142.0.7444.162/.163 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 升級 142.0.7444.162 (Linux) 或之後的版本
  • 升級 142.0.7444.162 (Mac) 或之後的版本
  • 升級 142.0.7444.162/.163 (Windows) 或之後的版本

漏洞識別碼


資料來源


相關連結

WordPress 遠端執行程式碼漏洞

WordPress 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 24 日 於 WordPress 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行任意程式碼。   注意 : 針對 WordPress 新發現的漏洞 CVE-202...