SUSE SLED15 / SLES15 Security Update : grafana (SUSE-SU-2022:3765-1)

The remote SUSE Linux SLED15 / SLES15 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:3765-1 advisory. - Grafana is an open-source platfor ...

Continue Reading
SUSE SLES15 Security Update : SUSE Manager Client Tools (SUSE-SU-2022:3751-1)

The remote SUSE Linux SLES15 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:3751-1 advisory. - Grafana is an open-source platform for mon ...

Continue Reading
SUSE SLES12 Security Update : SUSE Manager Client Tools (SUSE-SU-2022:3747-1)

The remote SUSE Linux SLES12 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:3747-1 advisory. - client_golang is the instrumentation libra ...

Continue Reading
(RHSA-2022:7273) Moderate: Red Hat JBoss Web Server 5.7.0 release and security update

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_clus ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Apache Pulsar: Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. ...

Continue Reading

CVSS3 - HIGH

Apache Pulsar: Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. ...

Continue Reading

CVSS3 - HIGH

WP OAuth Server < 4.2.2 – Admin+ Stored XSS

The plugin does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa ...

Continue Reading
WP OAuth Server < 4.2.2 – Admin+ Stored XSS

The plugin does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa ...

Continue Reading

Back to Main

Subscribe for the latest news: