Bref Doesn’t Support Multiple Value Headers in ApiGatewayFormatV2

Impacted Resources bref/src/Event/Http/HttpResponse.php:61-90 Description When Bref is used in combination with an API Gateway with the v2 format, it does not handle multiple values headers. Precisely ...

Continue Reading
Bref vulnerable to Body Parsing Inconsistency in Event-Driven Functions

Impacted Resources bref/src/Event/Http/Psr7Bridge.php:130-168 Description When Bref is used with the Event-Driven Function runtime and the handler is a RequestHandlerInterface, then the Lambda event i ...

Continue Reading
CVE-2023-49617

The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without ...

Continue Reading
K000138452 : Intel CPU BIOS vulnerabilities CVE-2023-25756 and CVE-2023-22329

Security Advisory Description CVE-2023-25756 Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via ad ...

Continue Reading
X.Org X Server regression

Releases Ubuntu 18.04 ESM Ubuntu 16.04 ESM Packages xorg-server - X.Org X11 server USN-6587-1 fixed vulnerabilities in X.Org X Server. The fix was incomplete resulting in a possible regression. Th ...

Continue Reading
CVE-2024-24557

Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to ...

Continue Reading
Security Bulletin: There is a vulnerability in kafka-clients-2.8.2.jar used by IBM Maximo Asset Management application (CVE-2023-25194)

Summary There is a vulnerability in kafka-clients-2.8.2.jar used by IBM Maximo Asset Management application. Vulnerability Details ** CVEID: CVE-2023-25194 DESCRIPTION: **Apache Kafka could allow a r ...

Continue Reading
Security Bulletin: There is a vulnerability in kafka-clients-2.8.2.jar used by IBM Maximo Manage application in IBM Maximo Application Suite (CVE-2023-25194)

Summary There is a vulnerability in kafka-clients-2.8.2.jar used by IBM Maximo Manage application in IBM Maximo Application Suite. Vulnerability Details ** CVEID: CVE-2023-25194 DESCRIPTION: **Apache ...

Continue Reading

Back to Main

Subscribe for the latest news: