CVE-2022-4148

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
CVE-2022-3894

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
CVE-2023-1421

A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a m ...

Continue Reading
Cross-Site Request Forgery (CSRF)

next-auth is vulnerable to Cross-Site Request Forgery (CSRF). The vulnerability exists due to the missing `state`, `nonce`, and `PKCE` checks for OAuth authentication, which allows an attacker to bypa ...

Continue Reading
Insufficient Session Expiration in pretix

rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.Read More ...

Continue Reading

CVSS3 - HIGH

Insufficient Session Expiration in pretix

rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.Read More ...

Continue Reading

CVSS3 - HIGH

This Week in Spring – March 14th, 2023

Hi, Spring fans! Happy Pi (π) day! And, welcome to another installment of _This Week in Spring_! It's pouring cats and dogs here in San Francisco! The news is talking about _atmospheric rivers_; I ...

Continue Reading
Missing proper state, nonce and PKCE checks for OAuth authentication

### Impact `next-auth` applications using OAuth provider versions before `v4.20.1` are affected. A bad actor who can spy on the victim's network or able to social engineer the victim to click a manipu ...

Continue Reading

Back to Main

Subscribe for the latest news: