Not All Sandboxes Are for Children: How to Secure Your SaaS Sandbox

[![](https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEiKwTAQRX-lSHb8mUXTtmveNwDZ4kH1YWeqKj6g3esXyruWtKog0Htu8tr1pUMY6zgnNVVZPOf0jwz6Ev7s4V8P0aDjbANDT4zkooXpEAdcVAAILEZsDbEykOt3rLTRSJoziBwS321 ...

Continue Reading
Ruby vulnerabilities CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325

* [CVE-2019-8322]() An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is cr ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2022-21595

Vulnerability in the MySQL Server product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows ...

Continue Reading

CVSS3 - MEDIUM

Jenkins Contrast Continuous Application Security Plugin vulnerable to stored Cross-site Scripting

Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XS ...

Continue Reading
Jenkins Contrast Continuous Application Security Plugin vulnerable to stored Cross-site Scripting

Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XS ...

Continue Reading
CVE-2022-1414

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access to sensitive inform ...

Continue Reading
Jenkins Katalon Plugin stores API keys unencrypted

Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to th ...

Continue Reading
Jenkins Katalon Plugin stores API keys unencrypted

Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to th ...

Continue Reading

Back to Main

Subscribe for the latest news: