CVE-2024-52287 authentik performs insufficient validation of OAuth scopes

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven' ...

Continue Reading
This Week in Spring – November 19th, 2024

Hi, Spring fans! How are you? Can you believe we're already staring at the end of the month? It's that time of the year when we see new releases, and the new releases reflect that frenzy! So ...

Continue Reading
Fedora: Security Advisory (FEDORA-2024-e7bb8bc2da)

The remote host is missing an update for...Read More ...

Continue Reading
Fedora: Security Advisory (FEDORA-2024-727ecb90c7)

The remote host is missing an update for...Read More ...

Continue Reading
K000148606: Spring vulnerability CVE-2021-22119

Security Advisory Description Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack v ...

Continue Reading
grafana security update

[10.2.6-4] - Resolves RHEL-44874 [10.2.6-3] - Resolves RHEL-35937 [10.2.6-2] - Fixes patch 1002 for update to golang-fips - Remove unused code under apsl-1.1 and apsl-1.2 licenses - Resolves RHEL-3365 ...

Continue Reading
Moderate: mod_auth_openidc security update

The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server. ...

Continue Reading
Moderate: mod_auth_openidc security update

The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server. ...

Continue Reading

Back to Main

Subscribe for the latest news: