Researchers Disclose Critical Vulnerability in Oracle Cloud Infrastructure

[![Oracle Cloud Infrastructure (OCI) vulnerability](https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEhTcO_BY91C6GxYfk6bo7VJ3lVRqDOnQ27OobTB4KFM3HHEwZRqHXsZBjTn5pRcjF9zxKMll-jQcfYKgQhYOIDCw04S ...

Continue Reading
(RHSA-2022:6681) Important: OpenShift Virtualization 4.9.6 Images security and bug fix update

This advisory contains the following OpenShift Virtualization 4.9.6 images: RHEL-8-CNV-4.9 ============== cnv-must-gather-container-v4.9.6-7 kubevirt-template-validator-container-v4.9.6-6 kubevirt-ssp ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

[SECURITY] Fedora 36 Update: libconfuse-3.3-7.fc36

libConfuse is a configuration file parser library, licensed under the terms of the ISC license, and written in C. It supports sections and (lists of) values (strings, integers, floats, booleans or oth ...

Continue Reading

CVSS3 - HIGH

[SECURITY] Fedora 35 Update: libconfuse-3.3-7.fc35

libConfuse is a configuration file parser library, licensed under the terms of the ISC license, and written in C. It supports sections and (lists of) values (strings, integers, floats, booleans or oth ...

Continue Reading

CVSS3 - HIGH

fhir-works-on-aws-authz-smart handles permissions improperly

### Impact This issue allows a client of the API to retrieve more information than the client’s OAuth scope permits when making “search-type” requests. This issue would not allow a client to retrie ...

Continue Reading
Bitbucket Git Command Injection

Various versions of Bitbucket Server and Data Center are vulnerable to an unauthenticated command injection vulnerability in multiple API endpoints. The `/rest/api/latest/projects/{projectKey}/repos/{ ...

Continue Reading
fhir-works-on-aws-authz-smart handles permissions improperly

### Impact This issue allows a client of the API to retrieve more information than the client’s OAuth scope permits when making “search-type” requests. This issue would not allow a client to retrie ...

Continue Reading
CVE-2022-41225

Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable ...

Continue Reading

Back to Main

Subscribe for the latest news: