CVE-2023-27496

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the OAuth filter assumes that a `state` query param ...

Continue Reading

CVSS3 - HIGH

CVE-2023-27496

A flaw was found in Envoy. If Envoy is running with the OAuth filter enabled, a malicious actor could construct a request which would cause denial of service, crashing Envoy.Read More ...

Continue Reading

CVSS3 - HIGH

MERCURY and DEV-1084: Destructive attack on hybrid environment

> **April 2023 update** – Microsoft Threat Intelligence has shifted to a new threat actor naming taxonomy aligned around the theme of weather. **MERCURY** is now tracked as **Mango Sandstorm** ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

MERCURY and DEV-1084: Destructive attack on hybrid environment

> **April 2023 update** – Microsoft Threat Intelligence has shifted to a new threat actor naming taxonomy aligned around the theme of weather. **MERCURY** is now tracked as **Mango Sandstorm** ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Github token with wide access to Nuxt related repositories leaked in the wild

# Description If you visit https://nuxt.com, you will find hardcoded Github token in the source code of the page - `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`. This token has access to multiple reposit ...

Continue Reading

CVSS3 - CRITICAL

Jenkins Enterprise and Operations Center 2.346.x < 2.346.40.0.15 Multiple Vulnerabilities (CloudBees Security Advisory 2023-04-12)

The version of Jenkins Enterprise or Jenkins Operations Center running on the remote web server is 2.346.x prior to 2.346.40.0.15. It is, therefore, affected by multiple vulnerabilities including the ...

Continue Reading

CVSS3 - HIGH

Fedora 37 : gh / golang-github-cenkalti-backoff / golang-github-cli-crypto / etc (2023-cb20f08a4e)

The remote Fedora 37 host has packages installed that are affected by a vulnerability as referenced in the FEDORA-2023-cb20f08a4e advisory. - A maliciously crafted HTTP/2 stream could cause excessiv ...

Continue Reading

CVSS3 - HIGH

[SECURITY] Fedora 37 Update: golang-github-cli-oauth-1.0.1-2.fc37

A library for performing OAuth Device flow and Web application flow in Go client apps.Read More ...

Continue Reading

CVSS3 - HIGH

Back to Main

Subscribe for the latest news: