VMWare Aria Operations for Networks (vRealize Network Insight) is vulnerable to command injection when accepting user input through the Apache Thrift RPC interface. This vulnerability allows a remote ...
Continue ReadingJuly 25, 2023
github.com/cometbft/cometbft is vulnerable to Denial of Service (DoS) attacks. A deadlock is introduced when serializing the struct `PeerState` to JSON when the new method `MarshallJSON` is used. One ...
Continue ReadingJuly 20, 2023
![Old Blackmoon Trojan, NEW Monetization Approach](https://blog.rapid7.com/content/images/2023/07/GettyImages-1187008408--1-.jpg) Rapid7 is tracking a new, more sophisticated and staged campaign using ...
Continue ReadingJuly 13, 2023
CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many machines. An internal modification made in versions 0.34.28 and 0.37.1 to the wa ...
Continue ReadingJuly 07, 2023
### Impact An internal modification to the way struct `PeerState` is serialized to JSON introduced a deadlock when new function MarshallJSON is called. This function can be called from two places: 1. ...
Continue ReadingJuly 07, 2023
### Impact An internal modification to the way struct `PeerState` is serialized to JSON introduced a deadlock when new function MarshallJSON is called. This function can be called from two places: 1. ...
Continue ReadingJuly 07, 2023
An internal modification to the way PeerState is serialized to JSON introduced a deadlock when the new function MarshalJSON is called. This function can be called in two ways. The first is via logs, b ...
Continue ReadingJuly 07, 2023
Back to Main