### Impact An attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter, which internally we convert to a `URL` object. The URL instantiation would fail due ...
Continue ReadingJune 21, 2022
### Impact An attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter, which internally we convert to a `URL` object. The URL instantiation would fail due ...
Continue ReadingJune 21, 2022
### Impact All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by ...
Continue ReadingJune 21, 2022
### Impact All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by ...
Continue ReadingJune 21, 2022
# [ safeguards organizations from any financial losses relating to damage to (or loss of) information from, networ ...
Continue ReadingJune 21, 2022
 ToddyCat is a relatively new APT actor that we have not been able to relate to ot ...
Continue ReadingJune 21, 2022
Back to Main