CVE-2024-42473 OpenFGA Authorization Bypass

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset ...

Continue Reading
CVE-2024-42473 OpenFGA Authorization Bypass

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset ...

Continue Reading
CVE-2024-42366 VR Overlay RCE

VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site scripting via overlay notification can be combined to res ...

Continue Reading
Malicious code in postman-open-technologies-knowledge-base-api (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (a0f1159812781f3847a9da7e6b4455cd3f3ee8bd00da0eddbe589dd52d1d56e8) The OpenSSF Package Analysis project identified & ...

Continue Reading
CVE-2024-43167 Unbound: null pointer dereference in unbound

A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. Wh ...

Continue Reading
Spring AI Embraces OpenAI’s Structured Outputs: Enhancing JSON Response Reliability

OpenAI recently introduced a powerful feature called Structured Outputs, which ensures that AI-generated responses adhere strictly to a predefined JSON schema. This feature significantly improves the ...

Continue Reading
Arbitrary File Read

org.jenkins-ci.main, jenkins-core and org.jenkins-ci.main, remoting are vulnerable to Arbitrary File Read. The vulnerability is caused due to a missing validation on the file paths that are invoked on ...

Continue Reading
CVE-2024-43167

A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. Wh ...

Continue Reading

Back to Main

Subscribe for the latest news: