Missing Authentication for Critical Function

In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on en ...

Continue Reading
Missing Release of Resource after Effective Lifetime

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint ...

Continue Reading
Grocy <=4.0.2 – CSRF

...Read More ...

Continue Reading
Security Bulletin: IBM Watson Assistant for IBM Cloud Pak for Data is vulnerable to multiple Node.js vulnerabilities

Summary Multiple Node.js vulnerabilitiies have been identified that may affect IBM Watson Assistant for IBM Cloud Pak for Data. The vulnerabilities have been addressed. Refer to details for additional ...

Continue Reading
containerd: Multiple Vulnerabilities

Background containerd is a daemon with an API and a command line client, to manage containers on one machine. It uses runC to run containers according to the OCI specification. Description Multiple vu ...

Continue Reading
[SECURITY] Fedora 39 Update: gnutls-3.8.3-1.fc39

GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access t ...

Continue Reading
AlmaLinux 8 : tomcat (ALSA-2024:0539)

The remote AlmaLinux 8 host has packages installed that are affected by a vulnerability as referenced in the ALSA-2024:0539 advisory. Improper Input Validation vulnerability in Apache Tomcat.Tomcat f ...

Continue Reading
Oracle Linux 8 : tomcat (ELSA-2024-0539)

The remote Oracle Linux 8 host has packages installed that are affected by a vulnerability as referenced in the ELSA-2024-0539 advisory. Improper Input Validation vulnerability in Apache Tomcat.Tomca ...

Continue Reading

Back to Main

Subscribe for the latest news: