Internet Bug Bounty: [CVE-2023-22799] Possible ReDoS based DoS vulnerability in GlobalID

I made a report and patch at https://hackerone.com/reports/1696752. https://discuss.rubyonrails.org/t/cve-2023-22799-possible-redos-based-dos-vulnerability-in-globalid/82127 > There is a possible D ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Denial Of Service (DoS)

gitlab is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the lack of length validation of the library, which allows an attacker to create large issue descriptions via GraphQL, ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-38503

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Incorrect Permission Checking for GraphQL Subscriptions

### Summary CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Access to information you should not have access to when the permissions rely on `$CURRENT_USER` for filtering. ### Deta ...

Continue Reading
Incorrect Permission Checking for GraphQL Subscriptions

### Summary CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Access to information you should not have access to when the permissions rely on `$CURRENT_USER` for filtering. ### Deta ...

Continue Reading
Exploit for Vulnerability in Gitlab

# CVE-2021-4191 - GitLab User Enumeration GitLab is a widely-us...Read More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Exploit for Vulnerability in Gitlab

# CVE-2021-4191 - GitLab User Enumeration GitLab is a widely-us...Read More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

(RHSA-2023:3815) Important: Service Registry (container images) release and security update [2.4.3 GA]

This release of Red Hat Integration - Service Registry 2.4.3 GA includes the following security fixes. Security Fix(es): * keycloak: path traversal via double URL encoding (CVE-2022-3782) * jackson-da ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: