Cross-Site Leak

gitlab is vulnerable to Cross-Site Leak. The vulnerability exists in the OAuth flow, allowing an attacker to leak an OAuth access token by getting the victim to visit a malicious page with SafariRead ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Authorization Bypass

gitlab is vulnerable to Authorization Bypasses. This vulnerability occurs due to a flaw in the way that GitLab handles OAuth subscriptions. An attacker can exploit this vulnerability to generate OAuth ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

(RHSA-2023:4623) Important: Red Hat OpenShift Service Mesh 2.2.9 security update

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * envoy: Clie ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Authentication Bypass

sentry is vulnerable to Authentication Bypass. The vulnerability exists due to the lack of a OIDC signing token inside the authentication mechanism which allows an attacker with sufficient client-side ...

Continue Reading
Emerging Attacker Exploit: Microsoft Cross-Tenant Synchronization

[![Microsoft Cross-Tenant Synchronization](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Attackers continue to target Microsoft ...

Continue Reading
Sentry vulnerable to incorrect credential validation on OAuth token requests

### Impact An attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID m ...

Continue Reading
Sentry vulnerable to incorrect credential validation on OAuth token requests

### Impact An attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID m ...

Continue Reading
CVE-2023-39531

Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2, an attacker with sufficient client-side exploits could retrieve a valid access ...

Continue Reading

Back to Main

Subscribe for the latest news: