This Week in Spring – July 18th, 2023

Hi, Spring fans! Welcome to another installment of _This Week in Spring_! I'm in crazy cool Kuala Lumpur, Malaysia. If you're around, I'll be doing a presentation this [Thursday the 20th of July](), a ...

Continue Reading
JumpCloud Blames ‘Sophisticated Nation-State’ Actor for Security Breach

[![Security Breach](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() A little over a week after [JumpCloud reset API keys of custo ...

Continue Reading
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal

rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file o ...

Continue Reading
CVE-2023-3584

Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Over ...

Continue Reading
CVE-2023-38350

PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.Read More ...

Continue Reading
VX-API – Collection Of Various Malicious Functionality To Aid In Malware Development

[![](https://blogger.googleusercontent.com/img/a/AVvXsEgr1-BatudpOrTBboSnbnl6IeB-hs6G82lmwcjZh_mKB7ppPTvTNGLZ4-IGqwr0OMHSg70olQ842507FSuX4vqg-KC1LmeNlgvGoDywPNjkUTbKxUgoIcq7NmJcqg5gyodiEtwx6pATZKMcAGr ...

Continue Reading
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal

rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file o ...

Continue Reading
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal

rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file o ...

Continue Reading

Back to Main

Subscribe for the latest news: