Weave server API vulnerable to arbitrary file leak

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various commo ...

Continue Reading
CVE-2022-4003

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API...Read More ...

Continue Reading
CVE-2022-4003

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API...Read More ...

Continue Reading
CVE-2022-4002

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API...Read More ...

Continue Reading
CVE-2022-4001

An authentication bypass vulnerability could allow an attacker to access API functions without...Read More ...

Continue Reading
CVE-2022-4003

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API...Read More ...

Continue Reading
CVE-2022-4002

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API...Read More ...

Continue Reading
CVE-2022-4001

An authentication bypass vulnerability could allow an attacker to access API functions without...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: