...Read More ...
Continue ReadingAugust 15, 2024
This Metasploit module exploits OpenMetadata versions 1.2.3 and below by chaining an API authentication bypass using JWT tokens along with a SpEL injection vulnerability to achieve arbitrary command.. ...
Continue ReadingAugust 15, 2024
...Read More ...
Continue ReadingAugust 15, 2024
Magento 2 patch for CVE-2024-34102(aka CosmicSting) Another way(as an extension) to hotfix the security hole if you cannot apply the official patch or cannot upgrade Magento. Description Impact The at ...
Continue ReadingAugust 14, 2024
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. This module chains two vuln ...
Continue ReadingAugust 14, 2024
Summary IBM Sterling Connect:Direct Web Service is vulnerable to JJWT version 0.9.1. Connect:Direct Web Services has upgraded to version 0.12.5 to address CVE-2024-31033. Vulnerability Details ** CVEI ...
Continue ReadingAugust 09, 2024
Summary Lua is used by IBM Cloud Pak for Data as part of the web interface. (CVE-2024-33531) Vulnerability Details ** CVEID: CVE-2024-33531 DESCRIPTION: **lua-resty-jwt could allow a remote attacker ...
Continue ReadingAugust 08, 2024
Back to Main