Stash < 0.26.0 – SQL Injection

Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort...Read More ...

Continue Reading
Zimbra Collaboration Server 9.0.0 < 9.0.0 Patch 42, 10.0 < 10.0.10, 10.1.0 < 10.1.2 CSRF

According to its self-reported version number, Zimbra Collaboration Server is affected by a cross-site request forgery by disabling GraphQL GET methods via localconfig. A new local config attribute, z ...

Continue Reading
Security Bulletin: IBM® Engineering Requirements Management DOORS/DWA – Vulnerabilities addressed in IBM® License Key Server

Summary IBM Engineering Requirements Management DOORS Family is subject to multiple vulnerabilities in IBM License Key Server (LKS) Administration and Reporting Tool (ART) and Agent v9.0. Vulnerabilit ...

Continue Reading
(RHSA-2024:7670) Critical: Red Hat build of Quarkus 3.8.6.SP1 Security Update

This release of Red Hat build of Quarkus 3.8.6.SP1 contains security updates. For more information, see the release notes page listed in the References section. Security Fix(es): com.google.protobuf ...

Continue Reading
(RHSA-2024:7676) Critical: Red Hat build of Quarkus 3.2.12.SP1 Security Update

This release of Red Hat build of Quarkus 3.2.12.SP1 contains security updates. For more information, see the release notes page listed in the References section. Security Fix(es): com.google.protobu ...

Continue Reading
CVE-2024-6861

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication ke ...

Continue Reading
CVE-2024-47614

async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion ...

Continue Reading
Security Bulletin: There is a vulnerability in graphql-java-20.1.jar used by IBM Maximo Manage application in IBM Maximo Application Suite (CVE-2024-40094)

Summary There is a vulnerability in graphql-java-20.1.jar used by IBM Maximo Manage application in IBM Maximo Application Suite. Vulnerability Details CVEID:CVE-2024-40094 DESCRIPTION: GraphQL Java (a ...

Continue Reading

Back to Main

Subscribe for the latest news: