JVN#47404248: “Gunosy” App vulnerable to insertion of sensitive information into sent data (CWE-201)

"Gunosy" App provided by Gunosy Inc. contains the following vulnerability. Insertion of sensitive information into sent data (CWE-201) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA ...

Continue Reading
PT-2025-35542

"Gunosy" App contains a vulnerability where sensitive information may be included in the application's outbound communication. If a user accesses a crafted URL, an attacker may ...

Continue Reading
Security Bulletin: Due to use of Connect2id Nimbus JOSE+JWT, IBM Watson Studio in Cloud Pak for Data is affected by denial of service

Summary Connect2id Nimbus JOSE+JWT is used by Watson Studio in Cloud Pak for Data. Vulnerability Details CVEID:CVE-2023-52428 DESCRIPTION: In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can ...

Continue Reading
CVE-2025-4644

A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT ...

Continue Reading
CVE-2025-4643

Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (whic ...

Continue Reading
CVE-2025-30064

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an ...

Continue Reading
Linux Distros Unpatched Vulnerability : CVE-2025-54955

The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Ed ...

Continue Reading
hippo4j Includes Hard Coded Secret Key in JWT Creation

hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impe ...

Continue Reading

Back to Main

Subscribe for the latest news: