CVE-2023-27264

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.Read More ...

Continue Reading
CVE-2023-27266

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner' ...

Continue Reading
CVE-2022-45138

The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated ...

Continue Reading

CVSS3 - CRITICAL

5 reasons to adopt a Zero Trust security strategy for your business

Adopting [Zero Trust security]() for your enterprise is no longer a wish-list item—it’s a business imperative. The workplace today extends to almost anywhere, anytime, from any device. Siloe ...

Continue Reading
CVE-2023-26041

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Web applications and Project Loom

## Introduction Project Loom aims to bring "easy-to-use, high-throughput, lightweight concurrency" to the JRE. One feature introduced by Project Loom is virtual threads. In this blog post, we'll be ex ...

Continue Reading
Messages can still be seen on conversation after expiring when cron is misconfigured

## Description ### Impact When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. ### Patches It is ...

Continue Reading
CVE-2022-34908

An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. The ...

Continue Reading

Back to Main

Subscribe for the latest news: