Apache Pulsar: Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. ...

Continue Reading

CVSS3 - HIGH

Apache Pulsar: Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. ...

Continue Reading

CVSS3 - HIGH

Moderate: grafana security, bug fix, and enhancement update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. The following packages have been upgraded to a later upstream version: grafana (7.5.1 ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Description of the security update for SharePoint Server Subscription Edition: November 8, 2022 (KB5002296)

None ## Summary This security update resolves a Microsoft Word remote code execution vulnerability, Microsoft SharePoint Server remote code execution vulnerability, and Microsoft Word information disc ...

Continue Reading

CVSS3 - HIGH

Description of the security update for SharePoint Server 2019: November 8, 2022 (KB5002294)

None ## Summary This security update resolves a Microsoft SharePoint Server remote code execution vulnerability, Microsoft Word information disclosure vulnerability, and Microsoft Word remote code exe ...

Continue Reading

CVSS3 - HIGH

grafana security, bug fix, and enhancement update

[7.5.15-3] - resolve CVE-2022-1962 golang: go/parser: stack exhaustion in all Parse* functions - resolve CVE-2022-1705 golang: net/https: improper sanitization of Transfer-Encoding header - resolve CVE ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

(RHSA-2022:8057) Important: grafana security, bug fix, and enhancement update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. The following packages have been upgraded to a later upstream version: grafana (7.5.1 ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Apache SOAP XML External Entity Injection Vulnerability

Apache SOAP is used as a client-side library by the Apache Foundation to invoke SOAP services available elsewhere, and as a server-side tool to implement SOAP-accessible services. parser in the RPCRou ...

Continue Reading

CVSS3 - HIGH

Back to Main

Subscribe for the latest news: