Harbor fails to validate the user permissions when viewing Webhook policies

### Impact Harbor fails to validate the user permissions to view Webhook policies including relevant credentials configured in different projects the user doesn’t have access to, resulting in malicio ...

Continue Reading
Harbor fails to validate the user permissions when updating tag immutability policies

### Impact Harbor fails to validate the user permissions when updating tag immutability policies - API call: PUT /projects/{project_name_or_id}/immutabletagrules/{immutable_rule_id} By sending a req ...

Continue Reading
Harbor fails to validate the user permissions when updating tag immutability policies

### Impact Harbor fails to validate the user permissions when updating tag immutability policies - API call: PUT /projects/{project_name_or_id}/immutabletagrules/{immutable_rule_id} By sending a req ...

Continue Reading
Microsoft Windows Common Log File System Driver has an unspecified vulnerability

Microsoft Windows Common Log File System Driver is a Microsoft Corporation Common Log File System (CLFS) API that provides a high-performance, common log file subsystem that can be used by dedicated c ...

Continue Reading

CVSS3 - HIGH

How Uber was hacked in 2022

**What happened?** The first information about the incident was issued yesterday, September 15th, 2022. We know that a hacker called “Tea Pot” successfully accessed Uber infrastructure and critical ...

Continue Reading
Talos worker join token can be used to get elevated access level to the Talos API

### Impact Talos worker nodes use a join token to get accepted into the Talos cluster. A misconfigured Kubernetes environment may allow workloads to access the join token of the worker node. A malicio ...

Continue Reading

CVSS3 - HIGH

Talos worker join token can be used to get elevated access level to the Talos API

### Impact Talos worker nodes use a join token to get accepted into the Talos cluster. A misconfigured Kubernetes environment may allow workloads to access the join token of the worker node. A malicio ...

Continue Reading

CVSS3 - HIGH

JOSE vulnerable to resource exhaustion via specifically crafted JWE

The PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named `p2c` ([PBES2 Count](https://www.rfc-editor.org/rfc/rfc7518.html#section-4.8.1.2)), which determines how many PBKDF2 ...

Continue Reading

CVSS3 - MEDIUM

Back to Main

Subscribe for the latest news: