Helm vulnerable to denial of service through schema file

Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the _chartutil_ package that can cause a segmentation violation. Applications that use functions from the _chart ...

Continue Reading
Helm vulnerable to denial of service through through repository index file

Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the _repo_ package that can cause a segmentation violation. Applications that use functions from the _repo_ pack ...

Continue Reading
Shoplazza 1.1 Cross Site Scripting Vulnerability

Post ContentRead More ...

Continue Reading
Security Updates for Microsoft OneNote C2R (December 2022)

The Microsoft OneNote Products are missing a security update. It is, therefore, affected by a remote code execution vulnerability. Note that Nessus has not tested for these issues but has instead reli ...

Continue Reading
Security Updates for Microsoft Visio Products C2R (December 2022)

The Microsoft Visio Products are missing a security update. It is, therefore, affected by multiple remote code execution vulnerabilities. Note that Nessus has not tested for these issues but has inste ...

Continue Reading
Security Updates for Microsoft Dynamics NAV (Dec 2022)

The Microsoft Dynamics NAV install is missing a security update. It is, therefore, affected by a remote code execution vulnerability. Note that Nessus has not attempted to exploit this issue but has i ...

Continue Reading
(RHSA-2022:9047) Moderate: Migration Toolkit for Containers (MTC) 1.7.6 security and bug fix update

The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the M ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Server-side Request Forgery (SSRF)

cxf-core is vulnerable to server-side request forgery. The vulnerability exists due to the lack of URL encode in MTOM content-id, which allows an attacker to perform SSRF-style attacks on web services ...

Continue Reading

Back to Main

Subscribe for the latest news: