Security researchers have discovered billions of exposed records online, calling it the "mother of all breaches". However, the dataset doesn't seem to be from one single data br ...
Continue ReadingJanuary 23, 2024
Impact Since v1.3.0, we use our own Request object. This is great, but the url behavior is unexpected. In the standard API, if the URL contains .., here called "double dots", the URL ...
Continue ReadingJanuary 23, 2024
Summary API endpoint /api/v1/watch/<uuid>/history can be accessed by any unauthorized user. Details WatchHistory resource does not have @auth.check_token annotation, which means it can b ...
Continue ReadingJanuary 23, 2024
Summary API endpoint /api/v1/watch/<uuid>/history can be accessed by any unauthorized user. Details WatchHistory resource does not have @auth.check_token annotation, which means it can b ...
Continue ReadingJanuary 23, 2024
The version of webkitgtk4 installed on the remote host is prior to 2.42.3-3. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2-2024-2427 advisory. The issue was addre ...
Continue ReadingJanuary 23, 2024
The version of webkitgtk4 installed on the remote host is prior to 2.42.3-3. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2-2024-2427 advisory. The issue was addre ...
Continue ReadingJanuary 23, 2024
The version of webkitgtk4 installed on the remote host is prior to 2.42.3-3. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2-2024-2427 advisory. The issue was addre ...
Continue ReadingJanuary 23, 2024
The version of webkitgtk4 installed on the remote host is prior to 2.42.3-3. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2-2024-2427 advisory. The issue was addre ...
Continue ReadingJanuary 23, 2024
Back to Main