Insufficient Session Expiration in pretix

rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.Read More ...

Continue Reading

CVSS3 - HIGH

This Week in Spring – March 14th, 2023

Hi, Spring fans! Happy Pi (π) day! And, welcome to another installment of _This Week in Spring_! It's pouring cats and dogs here in San Francisco! The news is talking about _atmospheric rivers_; I ...

Continue Reading
Missing proper state, nonce and PKCE checks for OAuth authentication

### Impact `next-auth` applications using OAuth provider versions before `v4.20.1` are affected. A bad actor who can spy on the victim's network or able to social engineer the victim to click a manipu ...

Continue Reading
Missing proper state, nonce and PKCE checks for OAuth authentication

### Impact `next-auth` applications using OAuth provider versions before `v4.20.1` are affected. A bad actor who can spy on the victim's network or able to social engineer the victim to click a manipu ...

Continue Reading
Fastly Secret Disclosure Vulnerability

Fastly suffers from the poor practice of sending a temporary password in plaintext.Read More ...

Continue Reading
Fastly Secret Disclosure

Post ContentRead More ...

Continue Reading
CVE-2023-27490

NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authenticati ...

Continue Reading
Wordfence Intelligence Weekly WordPress Vulnerability Report (Feb 27, 2023 to Mar 5, 2023)

Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as [Wordfence Intelligence](). This database is continuously upd ...

Continue Reading

CVSS3 - MEDIUM

Back to Main

Subscribe for the latest news: