etcd vulnerable to TOCTOU of gateway endpoint authentication

The vulnerability was spotted due to unclear documentation of how the gateway handles endpoints validation. ### Detail The gateway only authenticates endpoints detected from DNS SRV records, and it o ...

Continue Reading
Weak Password Requirements

etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess o ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Improper Validation of Array Index

In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are be ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

URL Redirection to Untrusted Site (‘Open Redirect’)

This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an ar ...

Continue Reading

CVSS3 - MEDIUM

CVE-2022-39292

Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed ...

Continue Reading
In-Depth Look Into Data-Driven Science Behind Qualys TruRisk

Vulnerability Management is a foundational component of any cybersecurity program for the implementation of appropriate security controls and the management of cyber risk. Earlier this year Qualys int ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Researchers Detail Malicious Tools Used by Cyberespionage Group Earth Aughisky

[![Cyberespionage Group Earth Aughisky](https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEh2oCJyA4hqYgoIYo5sLDo6zyST7yixChzpN19weBowzU3D8upgHXF8UHl5AlzpEahQqhyg6HMVjJ3MetZFZnbURWCW9FhJNdlELhwE ...

Continue Reading
CVE-2022-39289

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, mo ...

Continue Reading

Back to Main

Subscribe for the latest news: