Cross-site Scripting (XSS)

com.liferay.oauth2.provider.service is vulnerable to Cross-site Scripting (XSS). The vulnerability exists in the OAuth 2.0 module's `OAuth2ProviderApplicationRedirect` class in the library, which allo ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

This Week in Spring – June 6th, 2023

Hi, Spring fans! Welcome to another installment of _This Week in Spring_! And what an insane week it's been! Long story short, I've spent 10-12 hours a day over the last five days migrating a dozen di ...

Continue Reading
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 22, 2023 to May 28, 2023)

Last week, there were 90 vulnerabilities disclosed in 77 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 29 Vulnerab ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

[SECURITY] Fedora 38 Update: mod_auth_openidc-2.4.13.2-1.fc38

This module enables an Apache 2.x web server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.Read More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-34224

In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possibleRead More ...

Continue Reading
This Week in Spring – May 30th, 2023

Hi, Spring fans! Welcome to another installment of _This Week in Spring_! This installment I write on the day of my daughter's High School graduation, an auspicious day indeed! There's a lot to get th ...

Continue Reading
PrinterLogic Build 1.0.757 XSS / SQL Injection / Authentication Bypass

Post ContentRead More ...

Continue Reading
Liferay Portal 7.4.3.4 < 7.4.3.49 Authentication Bypass

The Object module in Liferay Portal and Liferay DXP does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a ...

Continue Reading

Back to Main

Subscribe for the latest news: