[SECURITY] Fedora 37 Update: libgit2-1.3.2-1.fc37

libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any langu ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-0558

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it ...

Continue Reading
Microsoft Edge (Chromium) < 109.0.1343.27 Multiple Vulnerabilities

The version of Microsoft Edge installed on the remote Windows host is prior to 109.0.1343.27. It is, therefore, affected by multiple vulnerabilities as referenced in the January 26, 2023 advisory. - ...

Continue Reading
Debian DSA-5328-1 : chromium – security update

The remote Debian 11 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-5328 advisory. - Use after free in WebTransport. (CVE-2023-0471) - Use after ...

Continue Reading
Security Bulletin: IBM Planning Analytics Workspace is affected by vulnerabilties

## Summary IBM Planning Analytics Workspace is affected by vulnerabilities. Node.js is an open-source and cross-platform JavaScript runtime environment (CVE-2022-35255, CVE-2022-35256). Node-tar is a ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Initial debug-host handler implementation could leak information and facilitate denial of service

### Impact version 1.5.0 and 1.6.0 when using the new `debug-host` feature could expose unnecessary information about the host ### Patches Use 1.6.1 or newer ### Workarounds Downgrade to 1.4.0 or set ...

Continue Reading
Bypassing OGNL sandboxes for fun and charities

## Overview[]() Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. In the ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Threat Round up for January 20 to January 27

![Threat Round up for January 20 to January 27](https://blog.talosintelligence.com/content/images/2023/01/threat-roundup-2.jpg) Today, Talos is publishing a glimpse into the most prevalent threats we' ...

Continue Reading

Back to Main

Subscribe for the latest news: