Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audie ...
Continue ReadingJune 12, 2024
On May 21, 2024, Veeam revealed a severe flaw across its Veeam Backup Enterprise Manager (VBEM) web interface that enables an unauthenticated attacker to log into the web interface as any user. Offici ...
Continue ReadingJune 11, 2024
Hard-coded JWT secret allows authentication bypass in Veeam Recovery...Read More ...
Continue ReadingJune 11, 2024
Hard-coded JWT secret allows authentication bypass in Veeam Recovery...Read More ...
Continue ReadingJune 11, 2024
Hard-coded JWT secret allows authentication bypass in Veeam Recovery...Read More ...
Continue ReadingJune 11, 2024
github.com/openshift/telemeter/ is vulnerable to Authentication Bypass By Spoofing. The vulnerability is due to improper checks which allows an attacker to bypass the issue ("iss") c ...
Continue ReadingJune 11, 2024
github.com/kubernetes/kubernetes/ is vulnerable to Authentication Bypass By Spoofing. The vulnerability is due to improper issuers check which allows an attacker to bypass the issue ("iss& ...
Continue ReadingJune 11, 2024
The remote Redhat Enterprise Linux 8 host has one or more packages installed that are affected by a vulnerability that has been acknowledged by the vendor but will not be patched. python-jwt: Key con ...
Continue ReadingJune 09, 2024
Back to Main