cookiejar Regular Expression Denial of Service via Cookie.parse function

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `Cookie.parse` function and other aspects of the API, which use an insecure regula ...

Continue Reading
cookiejar Regular Expression Denial of Service via Cookie.parse function

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `Cookie.parse` function and other aspects of the API, which use an insecure regula ...

Continue Reading
Exploit for Command Injection in Atlassian Bitbucket

# CVE-2022-36804: Pre-Auth RCE in Atlassian Bitbucket Server A c...Read More ...

Continue Reading

CVSS3 - HIGH

CVE-2023-23314

An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary code via a crafted .ssh file.Read More ...

Continue Reading
Improper Access Control

apache_superset is vulnerable to Improper Access Control. The vulnerability exists in `api.py` due to explicitly enabling the `DASHBOARD_CACHE` feature which allows an unauthenticated user to access d ...

Continue Reading
Denial Of Service (DoS)

protobuf is vulnerable to Denial Of Service (DoS). The vulnerability is due to multiple instances of non-repeated embedded message inputs with repeated or unknown fields which cause the objects to be ...

Continue Reading

CVSS3 - HIGH

Threat Round up for January 13 to January 20

![Threat Round up for January 13 to January 20](https://blog.talosintelligence.com/content/images/2023/01/threat-roundup-1.jpg) Today, Talos is publishing a glimpse into the most prevalent threats we' ...

Continue Reading
CVE-2022-3918

A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URLRequest headers. In this vulnerability, a client can insert one or several CRLF ...

Continue Reading

Back to Main

Subscribe for the latest news: