Incorrect Permission Checking for GraphQL Subscriptions

### Summary CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Access to information you should not have access to when the permissions rely on `$CURRENT_USER` for filtering. ### Deta ...

Continue Reading
Exploit for Vulnerability in Gitlab

# CVE-2021-4191 - GitLab User Enumeration GitLab is a widely-us...Read More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Exploit for Vulnerability in Gitlab

# CVE-2021-4191 - GitLab User Enumeration GitLab is a widely-us...Read More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

(RHSA-2023:3815) Important: Service Registry (container images) release and security update [2.4.3 GA]

This release of Red Hat Integration - Service Registry 2.4.3 GA includes the following security fixes. Security Fix(es): * keycloak: path traversal via double URL encoding (CVE-2022-3782) * jackson-da ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

(RHSA-2023:3809) Moderate: Red Hat build of Quarkus 2.13.8 release and security update

This release of Red Hat build of Quarkus 2.13.8 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section. Security Fixe ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Vendure Cross Site Request Forgery vulnerability impacting all API requests

### Impact Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of authorization. By default the Cookie settings are insecure, having the SameSite setting as false whi ...

Continue Reading
Vendure Cross Site Request Forgery vulnerability impacting all API requests

### Impact Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of authorization. By default the Cookie settings are insecure, having the SameSite setting as false whi ...

Continue Reading
CSRF on /api/graphql query executing the mutations through GET requests

# Description Mutations are `saveRecord` or `createProcess` queries used in Graphql. SuiteCRM prevents CSRF in this functionality by sending a POST request with a X-Xsrf-Token header. the bug here is ...

Continue Reading

Back to Main

Subscribe for the latest news: