No, not every Social Security number in the U.S. was stolen

My current least favorite thing about the churn of social media that I've seen over the past week is waves of stories, posts and videos saying that every U.S. citizen's Social Security numbe ...

Continue Reading
GoAuthentik vulnerable to Insufficient Authorization for several API endpoints

Summary Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this: /api/v3/crypto/certificatekeypairs/<uuid>/v ...

Continue Reading
GoAuthentik vulnerable to Insufficient Authorization for several API endpoints

Summary Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this: /api/v3/crypto/certificatekeypairs/<uuid>/v ...

Continue Reading
REXML denial of service vulnerability

Impact The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser A ...

Continue Reading
REXML denial of service vulnerability

Impact The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser A ...

Continue Reading
CVE-2024-43398 REXML denial of service vulnerability

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrus ...

Continue Reading
CVE-2024-43398

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrus ...

Continue Reading
CVE-2024-42490 authentik has Insufficient Authorization for several API endpoints

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/c ...

Continue Reading

Back to Main

Subscribe for the latest news: