Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the existing session on login. This allows attackers to use social engineering techniques to gain administrator access to Jenkins. As of p ...
Continue Reading17 мая, 2023
The version of Jenkins Enterprise or Jenkins Operations Center running on the remote web server is 2.346.x prior to 2.346.40.0.17. It is, therefore, affected by multiple vulnerabilities including the ...
Continue Reading17 мая, 2023
A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the attacker's account.Read More ...
Continue Reading16 мая, 2023
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.Read More ...
Continue Reading16 мая, 2023
The remote Oracle Linux 9 host has packages installed that are affected by a vulnerability as referenced in the ELSA-2023-2161 advisory. - OAuthLib is an implementation of the OAuth request-signing ...
Continue Reading16 мая, 2023
Welcome to our April API newsletter, recapping some of the events of last month. This monthâs topic is Generative AI tools (e.g., ChatGPT) in cybersecurity. It â along with API Security â ...
Continue Reading16 мая, 2023
[![SaaS Security](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() It's easy to think high-tech companies have a security advantag ...
Continue Reading15 мая, 2023
The remote AlmaLinux 9 host has packages installed that are affected by a vulnerability as referenced in the ALSA-2023:2161 advisory. - OAuthLib is an implementation of the OAuth request-signing log ...
Continue Reading14 мая, 2023
Back to Main