CVE-2024-8775 Ansible: exposure of sensitive information in ansible vault files due to improper logging

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars ...

Continue Reading
CVE-2024-8775 Ansible: exposure of sensitive information in ansible vault files due to improper logging

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars ...

Continue Reading
[SECURITY] Fedora 41 Update: nextcloud-29.0.6-1.fc41

NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your d ...

Continue Reading
LiteLLM Server-Side Request Forgery (SSRF) vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the api_base parameter when making requests to POST /chat/compl ...

Continue Reading
CVE-2024-39924

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the ...

Continue Reading
Security Updates for Azure CycleCloud (September 2024)

The Azure CycleCloud product is missing security updates. It is, therefore, affected by the following vulnerability: A remote code execution vulnerability exists due to a disclosure of the storage cr ...

Continue Reading
Fundamentals of GraphQL-specific attacks

GraphQL vs REST APIs Developers are constantly exploring new technologies that can improve the performance, flexibility, and usability of applications. GraphQL is one such technology that has gained s ...

Continue Reading
CVE-2024-8269 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 – Unauthorized User Registration

The MStore API – Create Native Android &amp; iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due ...

Continue Reading

Back to Main

Subscribe for the latest news: