HackerOne: View Titles of Private Reports with pending email invitation

Summary: If a private report has a pending email invitation for collaboration, an anonymous user can see the title of the report. This only works for anonymous users, and the collaboration invitation ...

Continue Reading
HackerOne: View Titles of Private Reports with pending email invitation

Summary: If a private report has a pending email invitation for collaboration, an anonymous user can see the title of the report. This only works for anonymous users, and the collaboration invitation ...

Continue Reading
HackerOne: View Titles of Private Reports with pending email invitation

Summary: If a private report has a pending email invitation for collaboration, an anonymous user can see the title of the report. This only works for anonymous users, and the collaboration invitation ...

Continue Reading
CVE-2023-46942

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL...Read More ...

Continue Reading
GitHub: RC Between GitHub’s Repo Transfer REST API and updateTeamsRepository GraphQL Mutation Results in Covert and Persistent Admin Access Retention

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the trans ...

Continue Reading
GitLab < 15.6.7 (SECURITY-RELEASE-GITLAB-15-8-1-RELEASED)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before ...

Continue Reading
Security Bulletin: IBM Security QRadar Analyst Workflow app for IBM QRadar SIEM is vulnerable to using components with known vulnerabilities

Summary The product includes vulnerable components (e.g., framework libraries) that might be identified and exploited with automated tools. IBM has addressed the vulnerabilities. Vulnerability Details ...

Continue Reading
GitLab 13.8 < 13.9.7 / 13.10 < 13.10.4 / 13.11 < 13.11.2 (CVE-2021-22209)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not ...

Continue Reading

Back to Main

Subscribe for the latest news: