CVE-2021-43445

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT a ...

Continue Reading
CVE-2021-4314

It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t ...

Continue Reading
Exploit for Use of a Broken or Risky Cryptographic Algorithm in Auth0 Jsonwebtoken

# CVE 2022-23540 In versions `Read More ...

Continue Reading

CVSS3 - CRITICAL

Exploit for Improper Input Validation in Auth0 Jsonwebtoken

# CVE-2022-23529 The JSON Web Token (JWT) library versions prio...Read More ...

Continue Reading
A User Can Unblock Themself

# Description `PUT /api/v1/users/{id}` API doesn't properly check the authorizaion. # Proof of Concept 1. [admin] Enable user registration functionality. 2. [user] Register new user and login as them. ...

Continue Reading
CVE-2023-22495

Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker ...

Continue Reading
Security Bulletin: A jwt-go vulnerability affects IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data (CVE-2020-26160)

## Summary A vulnerability in jwt-go affects IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data. Please see below for steps to address this issue. ## Vulnerability Details ** CVEID: **[CV ...

Continue Reading
Security Bulletin: IBM Cloud Pak for Security includes components with multiple known vulnerabilities

## Summary IBM Cloud Pak for Security includes components with known vulnerabilities. These have been updated in the latest release and vulnerabilities have been addressed. Please follow the instructi ...

Continue Reading

Back to Main

Subscribe for the latest news: