Apache Pulsar: Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. ...

Continue Reading

CVSS3 - HIGH

WP OAuth Server < 4.2.2 – Admin+ Stored XSS

The plugin does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa ...

Continue Reading
WP OAuth Server < 4.2.2 – Admin+ Stored XSS

The plugin does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa ...

Continue Reading
RHEL 8 : grafana (RHSA-2022:7519)

The remote Redhat Enterprise Linux 8 host has a package installed that is affected by multiple vulnerabilities as referenced in the RHSA-2022:7519 advisory. - sanitize-url: XSS due to improper sanit ...

Continue Reading
Moderate: grafana security, bug fix, and enhancement update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. The following packages have been upgraded to a later upstream version: grafana (7.5.1 ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Description of the security update for SharePoint Server Subscription Edition: November 8, 2022 (KB5002296)

None ## Summary This security update resolves a Microsoft Word remote code execution vulnerability, Microsoft SharePoint Server remote code execution vulnerability, and Microsoft Word information disc ...

Continue Reading

CVSS3 - HIGH

Description of the security update for SharePoint Server 2019: November 8, 2022 (KB5002294)

None ## Summary This security update resolves a Microsoft SharePoint Server remote code execution vulnerability, Microsoft Word information disclosure vulnerability, and Microsoft Word remote code exe ...

Continue Reading

CVSS3 - HIGH

CentOS 8 : grafana (CESA-2022:7519)

The remote CentOS Linux 8 host has a package installed that is affected by multiple vulnerabilities as referenced in the CESA-2022:7519 advisory. - sanitize-url: XSS due to improper sanitization in ...

Continue Reading

Back to Main

Subscribe for the latest news: