This Week in Spring – October 25th, 2022

Hi, Spring fans! Welcome to another installment of _This Week in Spring_! When last we spoke, I was in Las Vegas, NV, for the JavaOne show. It was _amazing_! I'm in sunny Singapore, then off to Malays ...

Continue Reading

CVSS3 - MEDIUM

Evolution of API Security – A Practical Guide to Addressing API Threats in 2023

The kind of API security scenarios we witnessed today were never like this from the beginning of time. It has gone to extra lengths to become responsive and productive as it’s now. _How was it ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server Liberty shipped with IBM Business Automation Workflow (CVE-2022-37734)

## Summary WebSphere Application Server Liberty is shipped as part of IBM Business Automation Workflow containers and as part of the optional components Process Federation Server (since 8.5.6), and Us ...

Continue Reading

CVSS3 - HIGH

CVE-2022-39382

Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `NODE_ENV` to trigger security-sensitive functionality in their production b ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-41876

ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated ...

Continue Reading
GraphQL queries can expose password hashes

### Impact Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically but not necessarily limited to administrators and edit ...

Continue Reading
GraphQL queries can expose password hashes

### Impact Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically but not necessarily limited to administrators and edit ...

Continue Reading
ezplatform-admin-ui vulnerable to Cross-Site Scripting (XSS)

It is possible to inject JavaScript XSS in the content type entries "name" and "short name". To exploit this, one must already have permission to edit content types, which limits it in many cases to p ...

Continue Reading

Back to Main

Subscribe for the latest news: