ECP SAML binding bypasses authentication flows

### Description A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentic ...

Continue Reading
CVE-2022-1026: Kyocera Net View Address Book Exposure

![CVE-2022-1026: Kyocera Net View Address Book Exposure](https://blog.rapid7.com/content/images/2022/03/kyocera-vuln.jpg) Rapid7 researcher Aaron Herndon has discovered that several models of Kyocera ...

Continue Reading
PHP vulnerabilities

Charles Fol discovered that PHP incorrectly handled initializing certain arrays when handling the pg_query_params function. A remote attacker could use this issue to cause PHP to crash, resulting in a ...

Continue Reading
Ubuntu 18.04 LTS / 20.04 LTS / 21.10 / 22.04 LTS : PHP vulnerabilities (USN-5479-1)

The remote Ubuntu 18.04 LTS / 20.04 LTS / 21.10 / 22.04 LTS host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-5479-1 advisory. Note that Nessus has not ...

Continue Reading
SUSE SLES12 Security Update : php74 (SUSE-SU-2022:1893-1)

The remote SUSE Linux SLES12 host has packages installed that are affected by a vulnerability as referenced in the SUSE- SU-2022:1893-1 advisory. Note that Nessus has not tested for this issue but has ...

Continue Reading
EulerOS 2.0 SP3 : php (EulerOS-SA-2022-1755)

According to the versions of the php packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities : - In PHP versions 7.3.x below 7.3.33, 7.4.x below ...

Continue Reading
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated u ...

Continue Reading
Overview of F5 vulnerabilities (May 2022)

On May 4, 2022, F5 announced the following security issues. This document is intended to serve as an overview of these vulnerabilities and security exposures to help determine the impact to your F5 de ...

Continue Reading

Back to Main

Subscribe for the latest news: