CVE-2021-22696

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). ...

Continue Reading
Microweber CMS 1.2.15 Account Takeover

Post ContentRead More ...

Continue Reading
Microweber CMS 1.2.15 – Account Takeover Vulnerability

Post ContentRead More ...

Continue Reading
Denial of service in Spring Security OAuth

Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 C ...

Continue Reading
Microweber CMS 1.2.15 – Account Takeover

Post ContentRead More ...

Continue Reading
Spring Security OAuth reaches End-of-Life

The [Spring Security OAuth]() and [Spring Security OAuth Boot 2 auto-configuration]() projects have reached end of life. The Spring Security OAuth project has been replaced by the Client and Resource ...

Continue Reading
CVE-2022-22969

Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 ...

Continue Reading
(RHSA-2022:2280) Important: OpenShift Container Platform 3.11.705 security update

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages ...

Continue Reading

Back to Main

Subscribe for the latest news: