OWASP Coraza WAF – A Golang Modsecurity Compatible Web Application Firewall Library

[![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDIwzcZLeJuzWXppUYD064RlCGG9G9U2dQuxJNspnaX5IkUJYrTV9Q1tyOejKNEMT9Ch2nj1zOgvipfnS8aeGwvnbEsypqT16iKLA99igOo36scdZAxHTug93PD2iwzF2_igKCwe ...

Continue Reading
Deserialization of Untrusted Data in Apache Dubbo

Apache Dubbo prior to 2.6.9 and 2.7.10 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the ser ...

Continue Reading
What is JSON-RPC ? Definition, Work, Comparison

Just like everything else, the world of API protocols is evolving. Typical [SOAP]() and REST APIs have many companies like GraphQL, gRPC, and Thrift. JSON-RPC is also on the list. Created to develop f ...

Continue Reading
API Security Tutorial

**Historial API Evolution** As per the documented history, the occurrence of web APIs transpired towards the end of 1990 with the launch of Salesforce’s sales automation solution. At that point in ti ...

Continue Reading
API security?—?Wiki: What is ? Why ? For PenTest & Best Practice

### API security — Wiki: What is ? Why ? For PenTest & Best Practice **What does api mean?** For beginners, API refers to the Application Programming Interface designed for effortless communicati ...

Continue Reading
Key confusion through non-blocklisted public key formats

### Impact _What kind of vulnerability is it? Who is impacted?_ Disclosed by Aapo Oksman (Senior Security Specialist, Nixu Corporation). > PyJWT supports multiple different JWT signing algorithms. ...

Continue Reading
Argo CD will blindly trust JWT claims if anonymous access is enabled

### Impact A critical vulnerability has been discovered in Argo CD which would allow unauthenticated users to impersonate as any Argo CD user or role, including the `admin` user, by sending a specific ...

Continue Reading
Argo CD will blindly trust JWT claims if anonymous access is enabled

### Impact A critical vulnerability has been discovered in Argo CD which would allow unauthenticated users to impersonate as any Argo CD user or role, including the `admin` user, by sending a specific ...

Continue Reading

Back to Main

Subscribe for the latest news: