CVE-2023-1387

Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it ...

Continue Reading
CVE-2023-30845

ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authentication bypass vulnerability. API clients can cra ...

Continue Reading
FreeBSD : Grafana — Exposure of sensitive information to an unauthorized actor (5e257b0d-e466-11ed-834b-6c3be5272acd)

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the 5e257b0d-e466-11ed-834b-6c3be5272acd advisory. - Gr ...

Continue Reading
Authentication Bypass

github.com/GoogleCloudPlatform/esp-v2 is vulnerable to Authentication Bypass. The vulnerability exists because the library does not properly filter the malicious HTTP headers, which allows an attacker ...

Continue Reading
Annotation tool: token forgery using jwt secret to claim super admin role

Although the annotator tool's source code is not directly provided in the repository a docker image is provided. From there it is easy to get access to the source code by either extracting the docker ...

Continue Reading
CBL Mariner 2.0 Security Update: python-jwt (CVE-2022-39227)

The version of python-jwt installed on the remote CBL Mariner 2.0 host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the CVE-2022-39227 advisory. - pytho ...

Continue Reading

CVSS3 - CRITICAL

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

[![ChatGPT](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() OpenAI on Friday disclosed that a bug in the Redis open source librar ...

Continue Reading
Amazon Linux 2023 : python3-jwt, python3-jwt+crypto (ALAS2023-2023-076)

It is, therefore, affected by a vulnerability as referenced in the ALAS2023-2023-076 advisory. - PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithm ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: