ocsinventory-server – security update

The source package ocsinventory-server has been updated to address the API change in php-cas due to [CVE-2022-39369](https://security-tracker.debian.org/tracker/CVE-2022-39369), see DLA 3485-1 for det ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

ruby:2.7 security, bug fix, and enhancement update

ruby [2.7.8-139] - Upgrade to Ruby 2.7.8. Resolves: rhbz#2149262 - Fix HTTP response splitting in CGI. Resolves: CVE-2021-33621 - Fix ReDoS vulnerability in URI. Resolves: CVE-2023-28755 - Fix R ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Connection Confusion

grpc is vulnerable to Connection Confusion. The vulnerability exists when the gRPC HTTP2 stack raised a header size exceeded error, and it skipped parsing the rest of the HPACK frame, which caused any ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Secrets, Secrets Are No Fun. Secrets, Secrets (Stored in Plain Text Files) Hurt Someone

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Secrets are meant to be hidden or, at the very least, only known to a specif ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Silentbob Campaign: Cloud-Native Environments Under Attack

[![Silentbob Campaign](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Cybersecurity researchers have unearthed an attack infrast ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Security Bulletin: Watson CP4D Data Stores is vulnerable to SAP NetWeaver AS for JAVA security bypass vulnerability ( CVE-2023-30744)

## Summary Potential SAP NetWeaver AS for JAVA security bypass vulnerability ( CVE-2023-30744) has been identified that may affect Watson CP4D Data Stores. Refer to details for additional information. ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Connection confusion in gRPC

When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Connection confusion in gRPC

When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: