GitHub Security Lab audited DataHub: Here’s what they found

At GitHub, we really care about open source security and love to help maintainers to secure their code. That is indeed the mission of the GitHub Security Lab. As users of open source software (OSS), w ...

Continue Reading

CVSS3 - CRITICAL

CVE-2023-26051

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. S ...

Continue Reading
CVE-2023-26052

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. S ...

Continue Reading
api-platform/core’s secured properties may be accessible within collections

API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatformMetadataApiProperty` attribute can be ...

Continue Reading
CVE-2023-25575

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Security Bulletin: CVE-2022-37734 may affect IBM CICS TX Advanced

## Summary WebSphere Application Server Liberty is vulnerable to denial of service due to GraphQL Java. This affects IBM WebSphere Liberty used by IBM CICS TX Advanced. IBM CICS TX Advanced has addres ...

Continue Reading

CVSS3 - HIGH

Security Bulletin: CVE-2022-37734 may affect IBM CICS TX Standard

## Summary WebSphere Application Server Liberty is vulnerable to denial of service due to GraphQL Java. This affects IBM WebSphere Liberty used by IBM CICS TX Standard. IBM CICS TX Standard has addres ...

Continue Reading

CVSS3 - HIGH

CVE-2023-0886

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue descript ...

Continue Reading

Back to Main

Subscribe for the latest news: