SQL injection in API authorization check

# Description TeamPass `/authorize` API endpoint is vulnerable to SQL injection in the `login` field. It is possible to forge an arbitrary Blowfish hash and use it in the query to bypass the password ...

Continue Reading
SUSE SLED15 / SLES15 / openSUSE 15 Security Update : python-PyJWT (SUSE-SU-2023:0794-1)

The remote SUSE Linux SLED15 / SLES15 / openSUSE 15 host has a package installed that is affected by a vulnerability as referenced in the SUSE-SU-2023:0794-1 advisory. - PyJWT is a Python implementa ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-27583

PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any ac ...

Continue Reading
Predictions for 2023 from Latest API Threat Research | API Security Newsletter

March has arrived and is roaring like a very confused lion, at least in the northern hemisphere. And much like in the wild, brood production is increasing. We've already seen some fruits of that labor ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

CVE-2023-25403

CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A ...

Continue Reading
GitHub Security Lab audited DataHub: Here’s what they found

At GitHub, we really care about open source security and love to help maintainers to secure their code. That is indeed the mission of the GitHub Security Lab. As users of open source software (OSS), w ...

Continue Reading

CVSS3 - CRITICAL

Privilege Escalation

github.com/mosn/mosn is vulnerable to Privilege Escalation. The vulnerability exists due to the `prefixMatcher` function in `matcher.go` while using JWT authorization, which is case-sensitive to the p ...

Continue Reading

CVSS3 - CRITICAL

CVE-2023-26032

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain SQL Injection via ma ...

Continue Reading

Back to Main

Subscribe for the latest news: