# Description wallabag was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete API key via `/developer/client/delete/{id}` This vulnerability has a ...
Continue ReadingAugust 21, 2023
# Description wallabag was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete API key via `/developer/client/delete/{id}` This vulnerability has a ...
Continue ReadingAugust 21, 2023
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due t ...
Continue ReadingAugust 21, 2023
[]() From a user's perspective, OAuth works like magic. ...
Continue ReadingAugust 21, 2023
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy pri ...
Continue ReadingAugust 21, 2023
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.35.0, pipelines do not validate child UIDs, which means that a user that has access to ...
Continue ReadingAugust 21, 2023
[![](https://blogger.googleusercontent.com/img/a/AVvXsEjbqMpCBUUuH_Cebb86EAw3o01arD1MdWw1KdtOCRSkwF81E7-nCpouAZZpYj6IJCOF6T5uKeSTVMlN4gsmfXObLsJ37Dk5lk1fiQ0acqK_XK8MTP2ZIJd8sUlgLfrrsLvzuM3ur23Sx8lf_VB ...
Continue ReadingAugust 20, 2023
Back to Main