Ingress-nginx `path` sanitization can be bypassed with newline character

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` f ...

Continue Reading
Security Bulletin: Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak.

## Summary Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. OpenSSL is used by IBM Robotic Process Automation as part of the API Server (CVE-2022-4304, CVE-20 ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Screen SFT DAB 600/C – Authentication Bypass Admin Password Change Exploit

Post ContentRead More ...

Continue Reading
SSCMS vulnerable to Cross Site Scripting

A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file `/api/stl/actions/search`. The manipulation of the argument a ...

Continue Reading
Synapse does not apply enough checks to servers requesting auth events of events in a room

### Impact The Matrix Federation API allows remote homeservers to request the *authorisation events* of events in a room. This is necessary so that a homeserver receiving some events can validate that ...

Continue Reading
Synapse Denial of service due to incorrect application of event authorization rules during state resolution

### Impact If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current sta ...

Continue Reading
Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites

### Impact A malicious user on a Synapse homeserver X with permission to create certain state events can disable outbound federation from X to an arbitrary homeserver Y. Synapse instances with federat ...

Continue Reading
Screen SFT DAB 600/C – Authentication Bypass Account Creation Exploit

Post ContentRead More ...

Continue Reading

Back to Main

Subscribe for the latest news: