Microsoft discloses 5 critical vulnerabilities in June’s Patch Tuesday, no zero-days

![Microsoft discloses 5 critical vulnerabilities in June's Patch Tuesday, no zero-days](https://blog.talosintelligence.com/content/images/2023/06/patch-tuesday.png) Microsoft released its monthly secu ...

Continue Reading
GitHub Security Lab: Go : Add more JWT sinks

This bug was reported directly to GitHub Security Lab.Read More ...

Continue Reading
Information Disclosure

io.ktor is vulnerable to Information Disclosure. The vulnerability exists due to improper masking of credentials inside exception messages, which allows an attack to exfiltrate the JWT token by sendin ...

Continue Reading

CVSS3 - LOW

CVSS2 - LOW

CVE-2023-2827

SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent ...

Continue Reading
Exploit for Authentication Bypass by Spoofing in Python-Jwt Project Python-Jwt

# CVE-2022-39227 CVE-2022-39227 : Proof of Concept Proof of co...Read More ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

PocketMine-MP vulnerable to server crash with certain invalid JSON payloads in `LoginPacket` due to vulnerable dependency

### Impact An attacker could crash the server by sending malformed JWT JSON in `LoginPacket` due to a security vulnerability in [`netresearch/jsonmapper`](https://github.com/cweiske/JsonMapper), due t ...

Continue Reading
PocketMine-MP vulnerable to server crash with certain invalid JSON payloads in `LoginPacket` due to vulnerable dependency

### Impact An attacker could crash the server by sending malformed JWT JSON in `LoginPacket` due to a security vulnerability in [`netresearch/jsonmapper`](https://github.com/cweiske/JsonMapper), due t ...

Continue Reading
Moxa MXsecurity Series Hard-coded JWT Key Authentication Bypass (CVE-2023-33236)

The Moxa MXsecurity Series running on the remote host uses a hard-coded JWT key. An unauthenticated, remote attacker can exploit this, via a specially crafted message, to bypass authentication to perf ...

Continue Reading

Back to Main

Subscribe for the latest news: