(RHSA-2023:3809) Moderate: Red Hat build of Quarkus 2.13.8 release and security update

This release of Red Hat build of Quarkus 2.13.8 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section. Security Fixe ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Vendure Cross Site Request Forgery vulnerability impacting all API requests

### Impact Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of authorization. By default the Cookie settings are insecure, having the SameSite setting as false whi ...

Continue Reading
Vendure Cross Site Request Forgery vulnerability impacting all API requests

### Impact Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of authorization. By default the Cookie settings are insecure, having the SameSite setting as false whi ...

Continue Reading
CSRF on /api/graphql query executing the mutations through GET requests

# Description Mutations are `saveRecord` or `createProcess` queries used in Graphql. SuiteCRM prevents CSRF in this functionality by sending a POST request with a X-Xsrf-Token header. the bug here is ...

Continue Reading
Security Bulletin: The IBM® Engineering Lifecycle Engineering product using IBM WebSphere Application Server Liberty is vulnerable to GraphQL – CVE-2023-28867

## Summary Vulnerability in the GraphQL Java library used by IBM WebSphere Application Server Liberty when the feature mpGraphQL-1.0 or mpGraphQL-2.0 is enabled. Following IBM® Engineering Lifecycl ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

HackerOne: An attacker can can view any hacker email via /SaveCollaboratorsMutation operation name

**Summary:** An attacker can view any attacker or normal user email after send invitation via dummy report , disclose their private email. **Description:** ### Steps To Reproduce 1 - Create a dummy re ...

Continue Reading
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 26, 2023 to July 2, 2023)

Last week, there were 66 vulnerabilities disclosed in 56 WordPress Plugins and 1 WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 34 Vulnerabi ...

Continue Reading
Security Bulletin: A security vulnerabilities has been identified in IBM WebSphere Application Server Liberty shipped with IBM Business Automation Workflow (CVE-2023-28867)

## Summary WebSphere Application Server Liberty is shipped as part of IBM Business Automation Workflow containers and as part of the optional components Process Federation Server (since 8.5.6), and Us ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: