Denial Of Service (DoS)

gitlab is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the lack of length validation of the library, which allows an attacker to create a large Issue description via GraphQL, ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Sorare: Operation CreateOrUpdateSo5LineupMutation does not restrict multiple captains

## Summary: By tampering with the POST request to the endpoint CreateOrUpdateSo5LineupMutation while editing a team you can change all football players to have the captain attribute to 'true'. This g ...

Continue Reading
A Data Exfiltration Attack Scenario: The Porsche Experience

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() As part of [**Checkmarx's mission**]() to help organizations develop and dep ...

Continue Reading
Improper Permission Checks

directus is vulnerable to Improper Permission Checks. The vulnerability exists because the permission filters such as `user_created IS $CURRENT_USER` are not properly checked in the library when using ...

Continue Reading
Internet Bug Bounty: [CVE-2023-22799] Possible ReDoS based DoS vulnerability in GlobalID

I made a report and patch at https://hackerone.com/reports/1696752. https://discuss.rubyonrails.org/t/cve-2023-22799-possible-redos-based-dos-vulnerability-in-globalid/82127 > There is a possible D ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Denial Of Service (DoS)

gitlab is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the lack of length validation of the library, which allows an attacker to create large issue descriptions via GraphQL, ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-38503

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Incorrect Permission Checking for GraphQL Subscriptions

### Summary CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Access to information you should not have access to when the permissions rely on `$CURRENT_USER` for filtering. ### Deta ...

Continue Reading

Back to Main

Subscribe for the latest news: