FreeBSD : Grafana — Exposure of sensitive information to an unauthorized actor (5e257b0d-e466-11ed-834b-6c3be5272acd)

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the 5e257b0d-e466-11ed-834b-6c3be5272acd advisory. - Gr ...

Continue Reading
Authentication Bypass

github.com/GoogleCloudPlatform/esp-v2 is vulnerable to Authentication Bypass. The vulnerability exists because the library does not properly filter the malicious HTTP headers, which allows an attacker ...

Continue Reading
Annotation tool: token forgery using jwt secret to claim super admin role

Although the annotator tool's source code is not directly provided in the repository a docker image is provided. From there it is easy to get access to the source code by either extracting the docker ...

Continue Reading
CBL Mariner 2.0 Security Update: python-jwt (CVE-2022-39227)

The version of python-jwt installed on the remote CBL Mariner 2.0 host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the CVE-2022-39227 advisory. - pytho ...

Continue Reading

CVSS3 - CRITICAL

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

[![ChatGPT](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() OpenAI on Friday disclosed that a bug in the Redis open source librar ...

Continue Reading
Amazon Linux 2023 : python3-jwt, python3-jwt+crypto (ALAS2023-2023-076)

It is, therefore, affected by a vulnerability as referenced in the ALAS2023-2023-076 advisory. - PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithm ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

SQL injection in API authorization check

# Description TeamPass `/authorize` API endpoint is vulnerable to SQL injection in the `login` field. It is possible to forge an arbitrary Blowfish hash and use it in the query to bypass the password ...

Continue Reading
SUSE SLED15 / SLES15 / openSUSE 15 Security Update : python-PyJWT (SUSE-SU-2023:0794-1)

The remote SUSE Linux SLED15 / SLES15 / openSUSE 15 host has a package installed that is affected by a vulnerability as referenced in the SUSE-SU-2023:0794-1 advisory. - PyJWT is a Python implementa ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: