Authorization Bypass

quarkus-smallrye-graphql is vulnerable to Authorization Bypass. The vulnerability is due to doHandle function in SmallRyeGraphQLOverWebSocketHandler.java file there are no checks to ensure that the us ...

Continue Reading
Security Bulletin: IBM Edge Application Manager 4.5.2 addresses the security vulnerabilities listed in the CVEs below.

## Summary IBM Edge Application Manager 4.5.2 addresses the security vulnerabilities listed in the CVEs below. ## Vulnerability Details ** CVEID: **[CVE-2022-25883]() ** DESCRIPTION: **Node.js semver ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

This is the Beginning of the End of the N+1 Problem: Introducing Single Query Loading.

## TL;DR: Starting with Spring Data JDBC 3.2.0-M2, Spring Data JDBC supports _Single Query Loading_. Single Query Loading loads arbitrary aggregates with a single select statement. To enable Single Qu ...

Continue Reading
My SpringOne 2023 Recap

Hi, Spring fans! Look, it's Monday after the first in-person SpringOne of the 2020s and the first since the pandemic, and, being honest, I'm bushed! Vegas is a dizzying, sensational, overwhelming, exc ...

Continue Reading
HackerOne: IDOR – Delete all Licenses and certifications from users account using CreateOrUpdateHackerCertification GraphQL query

**Summary:** Hey team, While editing our **Licenses and certifications** if we change the ID number we can delete other users **Licenses and certifications**. it simply can be done by editing the ID n ...

Continue Reading
CVE-2023-0921

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue descri ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-40027

Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as `undefined`, the `adminMeta` GraphQL query is publicly accessible (no sessi ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Cross-site Scripting (XSS)

cockpit-hq/cockpit is vulnerable to Cross-site Scripting (XSS). The vulnerability exists in Rest/GraphQL viewer due to lack of escaping script tags which allows an attacker to inject and execute arbit ...

Continue Reading

Back to Main

Subscribe for the latest news: