Planet’s secret file is created with excessive permissions

### Impact The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but its permissions allowed the user's group and non-group to read the fil ...

Continue Reading
Planet’s secret file is created with excessive permissions

### Impact The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but its permissions allowed the user's group and non-group to read the fil ...

Continue Reading
Threat Roundup for May 5 to May 12

![Threat Roundup for May 5 to May 12](https://blog.talosintelligence.com/content/images/2023/05/threat-roundup-1.jpg) Today, Talos is publishing a glimpse into the most prevalent threats we've observe ...

Continue Reading
etcd Key name can be accessed via LeaseTimeToLive API

### Impact LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited t ...

Continue Reading
Solving Your Teams Secure Collaboration Challenges

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() In today's interconnected world, where organisations regularly exchange sens ...

Continue Reading
CVE-2023-32076

in-toto is a framework to protect supply chain integrity. The in-toto configuration is read from various directories and allows users to configure the behavior of the framework. The files are from dir ...

Continue Reading
CVE-2023-28522

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Access Control Bypass

drupal/core is vulnerable to Access Control Bypass. The API was not integrated with existing permission controls, resulting in access bypass for users who have access to revisions of content, but not ...

Continue Reading

CVSS3 - MEDIUM

Back to Main

Subscribe for the latest news: