SQLFluff users with access to config file, using `libary_path` may call arbitrary python code

### Impact In environments where untrusted users have access to the config files (e.g. `.sqlfluff`), there is a potential security vulnerability where those users could use the `library_path` config v ...

Continue Reading
SQLFluff users with access to config file, using `libary_path` may call arbitrary python code

### Impact In environments where untrusted users have access to the config files (e.g. `.sqlfluff`), there is a potential security vulnerability where those users could use the `library_path` config v ...

Continue Reading
Sentry CORS misconfiguration

### Impact The Sentry API incorrectly returns the `access-control-allow-credentials: true` HTTP header if the `Origin` request header ends with the `system.base-hostname` option of Sentry installation ...

Continue Reading
Sentry CORS misconfiguration

### Impact The Sentry API incorrectly returns the `access-control-allow-credentials: true` HTTP header if the `Origin` request header ends with the `system.base-hostname` option of Sentry installation ...

Continue Reading
CVE-2023-36829

Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly returns the access-control-allow-credentials: true H ...

Continue Reading
Fedora 37 : firefox (2023-5c979c4971)

The remote Fedora 37 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2023-5c979c4971 advisory. - When Firefox is configured to block storage of ...

Continue Reading
JumpCloud Resets API Keys Amid Ongoing Cybersecurity Incident

[![JumpCloud](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() JumpCloud, a provider of cloud-based identity and access management ...

Continue Reading
git-commit-info vulnerable to Command Injection

Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo() fails to sanitize its parameter commit, which later flows ...

Continue Reading

Back to Main

Subscribe for the latest news: