(RHSA-2024:7164) Important: Migration Toolkit for Containers (MTC) 1.8.4 security and bug fix update

The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the M ...

Continue Reading
(RHSA-2024:7205) Important: osbuild-composer security update

An image building service based on osbuild It is inspired by lorax-composer and exposes the same API. As such, it is a drop-in replacement. Security Fix(es): encoding/gob: golang: Calling Decoder.Dec ...

Continue Reading
K000141194: urllib3 vulnerability CVE-2018-25091

Security Advisory Description urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This ...

Continue Reading
90,000 WordPress Sites Affected by Arbitrary File Upload and Authentication Bypass Vulnerabilities in Jupiter X Core WordPress Plugin

📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugins and themes at no cost to vendors? Through October 7th, 2024, XSS vulnerabilities in all plugins and themes with > ...

Continue Reading
Security Bulletin: Vulnerability in Apache Solr affects IBM watsonx.data

Summary Apache Solr could allow a remote attacker to bypass security restrictions, caused by improper access control by the Configsets API. The checks in place to prevent such features can be circumve ...

Continue Reading
CVE-2024-8350 Uncanny Groups for LearnDash <= 6.1.0.1 – Missing Authorization to Authenticated (Group Leader+) User Group Add

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions u ...

Continue Reading
CVE-2024-6845 SmartSearchWP < 2.4.6 – Unauthenticated OpenAI Key Disclosure

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, th ...

Continue Reading
CVE-2024-8678 Revolut Gateway for WooCommerce <= 4.17.3 – Missing Authorization to Unauthenticated Order Status Update

The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions up ...

Continue Reading

Back to Main

Subscribe for the latest news: