Zepp 6.1.4-play User Account Enumeration Vulnerability

Post ContentRead More ...

Continue Reading
Gitlab 14.9 – Authentication Bypass Vulnerability

Post ContentRead More ...

Continue Reading
Heroku Forces User Password Resets Following GitHub OAuth Token Theft

[![Heroku Forces User Password Resets](https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEg15Z2d_xS5elVdgf0xSUYqiHRPanhvDc3o8p0Vx09SlFdq1BQDAfW13mhR2zYu63dhu11Dj1cdPhHiHiFtH5bPgZ6_Iv97KMZMz_d4j ...

Continue Reading
CVE-2021-22573

The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An ...

Continue Reading
Token Validation Bypass

Google OAuth Client is vulnerable to token validation bypass. The function IdTokenVerifier validate any token with custom payload as valid token if the token is properly signed.Read More ...

Continue Reading
VMware Workspace ONE Access Template Injection / Command Execution Exploit

This Metasploit module exploits CVE-2022-22954, an unauthenticated server-side template injection (SSTI) vulnerability in VMware Workspace ONE Access, to execute shell commands as the horizon user.Rea ...

Continue Reading
Exploit for Improper Authentication in Jetbrains Hub

# CVE-2022-25262 PoC + vulnerability details for CVE-2022-25262 ...Read More ...

Continue Reading
CVE-2021-22573

The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An ...

Continue Reading

Back to Main

Subscribe for the latest news: