CVE-2023-3128

A flaw was found in Grafana, which validates Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique across Azure AD tenants, which enables Grafana account takeo ...

Continue Reading
CVE-2023-3128

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication byp ...

Continue Reading
Generative-AI apps & ChatGPT: Potential risks and mitigation strategies

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() _Losing sleep over Generative-AI apps? You're not alone or wrong. According ...

Continue Reading
SUSE SLES15 / openSUSE 15 Security Update : SUSE Manager Client Tools (SUSE-SU-2023:2578-1)

The remote SUSE Linux SLES15 / openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:2578-1 advisory. - All versions of package trim ...

Continue Reading
SUSE SLED15 / SLES15 / openSUSE 15 Security Update : SUSE Manager Client Tools (SUSE-SU-2023:2575-1)

The remote SUSE Linux SLED15 / SLES15 / openSUSE 15 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:2575-1 advisory. - All versions of pac ...

Continue Reading
Security Bulletin: IBM Security Verify Governance uses components with known vulnerabilities (CVE-2021-22696, CVE-2021-30468, CVE-2020-1954)

## Summary Components with the following Known Vulnerabilities have been upgraded in IBM Security Verify Governance. ## Vulnerability Details ** CVEID: **[CVE-2021-22696]() ** DESCRIPTION: **Apache C ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Critical ‘nOAuth’ Flaw in Microsoft Azure AD Enabled Complete Account Takeover

[![Microsoft Azure AD OAuth](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() A security shortcoming in Microsoft Azure Active Dir ...

Continue Reading
Improper Authentication

doorkeeper is vulnerable to Improper Authentication. The vulnerability exists because user authentication is automatically processed without consent of the user if the authentication token matches, wh ...

Continue Reading

Back to Main

Subscribe for the latest news: