This Week in Spring – March 14th, 2023

Hi, Spring fans! Happy Pi (π) day! And, welcome to another installment of _This Week in Spring_! It's pouring cats and dogs here in San Francisco! The news is talking about _atmospheric rivers_; I ...

Continue Reading
Nomad Job Submitter Privilege Escalation Using Workload Identity

### Summary A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a user with the submit-job ACL capability can submit a job that can escalate to management-level ...

Continue Reading
Nomad Job Submitter Privilege Escalation Using Workload Identity

### Summary A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a user with the submit-job ACL capability can submit a job that can escalate to management-level ...

Continue Reading
CVE-2023-1299

HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.Read More ...

Continue Reading
SUSE SLES12 Security Update : nodejs18 (SUSE-SU-2023:0715-1)

The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:0715-1 advisory. - A privilege escalation vulnerability exist ...

Continue Reading

CVSS3 - HIGH

CVE-2023-23857

Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to acc ...

Continue Reading
CVE-2023-27268

SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an ...

Continue Reading
CVE-2022-25967

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. ** ...

Continue Reading

CVSS3 - HIGH

Back to Main

Subscribe for the latest news: