K000140414: UDP protocol vulnerability CVE-2024-2169

Security Advisory Description Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implemen ...

Continue Reading
Nova vulnerability

Releases Ubuntu 24.04 LTS Ubuntu 22.04 LTS Ubuntu 20.04 LTS Packages nova - OpenStack Compute cloud infrastructure Details Arnaud Morin discovered that Nova incorrectly handled certain raw format ...

Continue Reading
Denial Of Service (DoS)

github.com/argoproj/argo-cd is vulnerable to Denial of Service (DoS). The vulnerability is due to insufficient input validation and resource management for large JSON payloads at the /api/webhook endp ...

Continue Reading
CVE-2024-40634

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large ...

Continue Reading
Sentry vulnerable to stored Cross-Site Scripting (XSS)

Impact An unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, ...

Continue Reading
Tomcat vulnerabilities

Releases Ubuntu 18.04 ESM Ubuntu 16.04 ESM Ubuntu 14.04 ESM Packages tomcat7 - Servlet 3.0 and JSP 2.2 Java API classes Details It was discovered that the Tomcat SSI printenv command echoed user p ...

Continue Reading
CVE-2024-41661

reNgine is an automated reconnaissance framework for web applications. In versions 1.2.0 through 2.1.1, an authenticated command injection vulnerability in the WAF detection tool allows an authenticat ...

Continue Reading
Bitbucket Datacenter REST API allows non-admin users to query all groups and members of the group

h3. Issue Summary Non-admin users (any licensed user) can query all the groups and members of the groups using the below API [Groups API|https://developer.atlassian.com/server/bitbucket/rest/v819/api- ...

Continue Reading

Back to Main

Subscribe for the latest news: