Important: Red Hat Security Advisory: Submariner 0.17.6 bug fixes and container updates

Submariner 0.17.6 packages fix bugs and adds enhancements that are now available for Red Hat Advanced Cluster Management for Kubernetes version 2.10. Red Hat Product Security has rated this update as ...

Continue Reading
GHSA-M3MQ-F375-5VGH Vantage6 Server JWT secret not cryptographically secure

Impact The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some ext ...

Continue Reading
Important: Red Hat Security Advisory: Red Hat Multicluster GlobalHub 1.2.3 bug fixes and container updates

Red Hat multicluster global hub 1.2.3 General Availability release images, which provide enhancements, bug fixes, and updated container images. Red Hat Product Security has rated this update as havin ...

Continue Reading
Security Bulletin: IBM Storage Protect Server is susceptible to vulnerabilities due to golang-JWT (CVE-2024-51744)

Summary Golang JWT is used by the IBM Storage Protect Server OSSM and Object Agent component. The vulnerabilities in the product component have been addressed. Vulnerability Details CVEID:CVE-2024-51 ...

Continue Reading
Security Bulletin: IBM Storage Fusion Data Foundation is vulnerable to CVE-2025-27144 in different components

Summary Go is used by IBM Storage Fusion Data Foundation in csi-dirver, odf-cli-container, ocs-operator-container, msc-operator-container, odf-multicluster-operator-container, rook-ceph-operator and o ...

Continue Reading
CVE-2025-35940

The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL...Read M ...

Continue Reading
CVE-2025-43866

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, wh ...

Continue Reading
Use Of Insufficiently Random Values

vantage6 is vulnerable to Use of Insufficiently Random Values. The vulnerability is due to insecure randomness of UUID1 for auto-generating JWT secret keys, which is partially predictable and not cryp ...

Continue Reading

Back to Main

Subscribe for the latest news: