Sensitive Information leak via Log File in Kubernetes

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

How to mitigate OWASP vulnerabilities while staying in the flow

The pace and scale of security vulnerabilities is increasing. This is in spite of the fact that teams have been trying to keep their code secure for years. So, why are vulnerabilities still such a pro ...

Continue Reading
CVE-2021-36225

Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.Read More ...

Continue Reading
Yet More ImageMagick Vulnerabilities

ImageMagick is a popular open-source image manipulation library used by many websites and software applications to process and display images. A couple of vulnerabilities have recently been discovered ...

Continue Reading
Exploit for Out-of-bounds Write in Vmware Cloud Foundation

# Feb2023-CVE-2021-21974-OSINT Analysis of the ransom demands fr...Read More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

PixPirate: New Android Banking Trojan Targeting Brazilian Financial Institutions

[![Android Banking Trojan](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() A new Android banking trojan has set its eyes on Brazi ...

Continue Reading
CVE-2015-10072

A vulnerability classified as problematic was found in NREL api-umbrella-web 0.7.1. This vulnerability affects unknown code of the component Flash Message Handler. The manipulation leads to cross site ...

Continue Reading
Insecure Permissions issue in jeecg-boot

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.Read ...

Continue Reading

Back to Main

Subscribe for the latest news: