Service Rents Email Addresses for Account Signups

One of the most expensive aspects of any cybercriminal operation is the time and effort it takes to constantly create large numbers of new throwaway email accounts. Now a new service offers to help dr ...

Continue Reading
Synapse has improper checks for deactivated users during login

### Impact It may be possible for a deactivated user to login when using uncommon configurations. This only applies if any of the following are true: * [JSON Web Tokens are enabled for login](https:// ...

Continue Reading
Rancher UI has multiple Cross-Site Scripting (XSS) issues

### Impact Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in the Rancher UI. Cross-Site scripting allows a malicious user to inject code that is executed within another user' ...

Continue Reading
Rancher UI has multiple Cross-Site Scripting (XSS) issues

### Impact Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in the Rancher UI. Cross-Site scripting allows a malicious user to inject code that is executed within another user' ...

Continue Reading
Rancher vulnerable to Privilege Escalation via manipulation of Secrets

### Impact A vulnerability has been identified which enables [Standard users](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/ ...

Continue Reading
CVE-2023-34097

hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Attackers with access to ...

Continue Reading
CVE-2023-33524

Advent/SSC Inc. Tamale RMS Read More ...

Continue Reading
Kyverno resource with a deletionTimestamp may allow policy circumvention

### Impact In versions of Kyverno prior to 1.10.0, resources which have the `deletionTimestamp` field defined can bypass validate, generate, or mutate-existing policies, even in cases where the `valid ...

Continue Reading

Back to Main

Subscribe for the latest news: