go-grpc-compression has a zstd decompression bombing vulnerability

Impact A malicious user could cause a denial of service (DoS) when using a specially crafted gRPC request. The decompression mechanism for zstd did not respect the limits imposed by gRPC, allowing rap ...

Continue Reading
GHSA-236W-P7WF-5PH8 vulnerabilities

Vulnerabilities for packages: rabbitmq-cluster-operator, prometheus-beat-exporter, configmap-reload, k8sgpt, prometheus-bind-exporter, kube-state-metrics, secrets-store-csi-driver-provider-azure, terr ...

Continue Reading
GHSA-49GW-VXVF-FC2G vulnerabilities

Vulnerabilities for packages: rabbitmq-cluster-operator, prometheus-beat-exporter, configmap-reload, k8sgpt, prometheus-bind-exporter, kube-state-metrics, secrets-store-csi-driver-provider-azure, terr ...

Continue Reading
CVE-2024-24790 vulnerabilities

Vulnerabilities for packages: rabbitmq-cluster-operator, prometheus-beat-exporter, configmap-reload, k8sgpt, prometheus-bind-exporter, kube-state-metrics, secrets-store-csi-driver-provider-azure, terr ...

Continue Reading
CVE-2024-24789 vulnerabilities

Vulnerabilities for packages: rabbitmq-cluster-operator, prometheus-beat-exporter, configmap-reload, k8sgpt, prometheus-bind-exporter, kube-state-metrics, secrets-store-csi-driver-provider-azure, terr ...

Continue Reading
Fedora: Security Advisory for qt6-qtgrpc (FEDORA-2024-bfb8617ba3)

The remote host is missing an update for...Read More ...

Continue Reading
CVE-2024-35223

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app instead of the app token of the invoked app. This cau ...

Continue Reading
Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC

Summary An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. Details The OpenTelemetry Collector handles compressed HTTP requ ...

Continue Reading

Back to Main

Subscribe for the latest news: