CVE-2023-34450

CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many machines. An internal modification made in versions 0.34.28 and 0.37.1 to the wa ...

Continue Reading
CometBFT PeerState JSON serialization deadlock

### Impact An internal modification to the way struct `PeerState` is serialized to JSON introduced a deadlock when new function MarshallJSON is called. This function can be called from two places: 1. ...

Continue Reading
CometBFT PeerState JSON serialization deadlock

### Impact An internal modification to the way struct `PeerState` is serialized to JSON introduced a deadlock when new function MarshallJSON is called. This function can be called from two places: 1. ...

Continue Reading
Deadlock in github.com/cometbft/cometbft/consensus

An internal modification to the way PeerState is serialized to JSON introduced a deadlock when the new function MarshalJSON is called. This function can be called in two ways. The first is via logs, b ...

Continue Reading
Milesight MilesightVPN requestHandlers.js LoginAuth SQL injection vulnerability

# Talos Vulnerability Report ### TALOS-2023-1701 ## Milesight MilesightVPN requestHandlers.js LoginAuth SQL injection vulnerability ##### July 6, 2023 ##### CVE Number CVE-2023-22319 ##### SUMMARY A s ...

Continue Reading
Milesight MilesightVPN requestHandlers.js verifyToken authentication bypass vulnerability

# Talos Vulnerability Report ### TALOS-2023-1700 ## Milesight MilesightVPN requestHandlers.js verifyToken authentication bypass vulnerability ##### July 6, 2023 ##### CVE Number CVE-2023-22844 ##### S ...

Continue Reading
Mailchimp – Critical – Cross Site Request Forgery – SA-CONTRIB-2023-025

This module provides integration with Mailchimp, a popular email delivery service. A route related to OAuth authentication is not protected against a Cross Site Request Forgery attack.Read More ...

Continue Reading
Improper Authorization

org.keycloak:keycloak-server-spi-private and org.keycloak:keycloak-services are vulnerable to Improper Authorization. The vulnerability exists under certain pre-conditions which allows an attacker to ...

Continue Reading

Back to Main

Subscribe for the latest news: