EXNESS: Double forward slash breaks server-side restrictions & allows access to prohibited services from a partner account

Hi Team, There appears to be a weird bug here. Making an API call to the prohibited endpoint appended with double/multiple slash is breaking some server-side restrictions imposed upon a partner accoun ...

Continue Reading
Exploit for CVE-2022-23529

# CVE-2022-23529 The JSON Web Token (JWT) library versions prio...Read More ...

Continue Reading
Don’t Let API Leaks Sink Your Ship | API Security Newsletter

Leaks of API keys and other secrets. The industry has been abuzz with news about attacks – and the ongoing ripple effect – involving leaked API keys, credentials and other secrets. This adds ...

Continue Reading

CVSS3 - CRITICAL

Spring Cloud Azure 5.0 is now Generally Available

We're very pleased to announce that Spring Cloud Azure 5.0 is now generally available. This major release includes the following features, improvements, and documentation updates: * Compatible with ...

Continue Reading
Spring Cloud Azure 5.0 is now Generally Available

We're very pleased to announce that Spring Cloud Azure 5.0 is now generally available. This major release includes the following features, improvements, and documentation updates: * Compatible with ...

Continue Reading
Authentication Bypass

opensearch is vulnerable to Authentication Bypass. The vulnerability exists because the library does not properly handle white spaces in JWT roles which allow users to potentially claim roles that the ...

Continue Reading
Spring Cloud Azure 5.0 is now Generally Available

We're very pleased to announce that Spring Cloud Azure 5.0 is now generally available. This major release includes the following features, improvements, and documentation updates: * Compatible with ...

Continue Reading
JWT audience claim is not verified

### Impact All versions of Argo CD starting with v1.8.2 are vulnerable to an improper authorization bug causing the API to accept certain invalid tokens. OIDC providers include an `aud` (audience) cla ...

Continue Reading

Back to Main

Subscribe for the latest news: