Improper Authorization

modoboa is vulnerable to Improper Authorization. The vulnerability exists due to missing authorization checks on the `/api/v2/parameters/core/` API endpoint which allows an attacker to gain sensitive ...

Continue Reading

CVSS3 - CRITICAL

Command injection in OpenTSDB

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Amazon Linux AMI : tomcat7 (ALAS-2023-1738)

The version of tomcat7 installed on the remote host is prior to 7.0.109-1.42. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS-2023-1738 advisory. - Apache Commons Fi ...

Continue Reading

CVSS3 - HIGH

CVE-2017-20184

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any ...

Continue Reading

CVSS3 - HIGH

Amazon Linux 2023 : tomcat9, tomcat9-admin-webapps, tomcat9-el-3.0-api (ALAS2023-2023-176)

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2023-176 advisory. - The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back- ...

Continue Reading

CVSS3 - HIGH

Amazon Linux 2023 : ecs-service-connect-agent (ALAS2023-2023-165)

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2023-165 advisory. - Envoy is an open source edge and service proxy designed for cloud-native applications. Prior ...

Continue Reading

CVSS3 - CRITICAL

Amazon Linux 2023 : ecs-service-connect-agent (ALAS2023-2023-165)

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2023-165 advisory. - Envoy is an open source edge and service proxy designed for cloud-native applications. Prior ...

Continue Reading

CVSS3 - CRITICAL

Amazon Linux 2023 : ecs-service-connect-agent (ALAS2023-2023-165)

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2023-165 advisory. - Envoy is an open source edge and service proxy designed for cloud-native applications. Prior ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: