Username enumeration attack in goauthentik

## Summary Using a recovery flow with an identification stage an attacker is able to determine if a username exists. ## Impact Only setups configured with a recovery flow are impacted by this. Anyone ...

Continue Reading
Account takeover via password reset

# Description An attacker could predict all future password reset tokens due to the use of `RandomStringUtils.randomAlphanumeric` in `PasswordService`. An attacker could crack the random number genera ...

Continue Reading
CVE-2023-40577

Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute ...

Continue Reading
Cross-site Scripting (XSS)

github.com/prometheus/alertmanager is vulnerable to Cross-site Scripting (XSS). The vulnerability exists due to the lack of HTML sanitization in the `generatorURL` field of `Alert.elm`, which allows a ...

Continue Reading
This Week in Spring – August 29th, 2023 – the post SpringOne recovery blog

Hi, Spring fans! Welcome to another installment of _This Week in Spring_! I'm exhausted. Seriously. Last week was mental. If you need me, I'll be over sipping on a tea... But, before that, there's a t ...

Continue Reading
Username enumeration attack in goauthentik

## Summary Using a recovery flow with an identification stage an attacker is able to determine if a username exists. ## Impact Only setups configured with a recovery flow are impacted by this. Anyone ...

Continue Reading
CVE-2023-40577

Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute ...

Continue Reading
Introducing Free Wordfence Intelligence WordPress Vulnerability Webhook Notifications!

We’re incredibly excited to announce that we have launched a webhook integration for vulnerabilities as part of Wordfence Intelligence, which enables users to stay on top of the latest vulnerabil ...

Continue Reading

Back to Main

Subscribe for the latest news: