GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker acce ...
Continue ReadingJanuary 15, 2025
Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave serve ...
Continue ReadingJanuary 15, 2025
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker acce ...
Continue ReadingJanuary 15, 2025
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker acce ...
Continue ReadingJanuary 15, 2025
The remote host is missing an update for...Read More ...
Continue ReadingJanuary 15, 2025
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically...Read More ...
Continue ReadingJanuary 15, 2025
github.com/h44z/wg-portal is vulnerable to Open Redirection. The vulnerability is due to improper handling of OAuth (or OIDC) authentication backends, which can be exploited when a user visits a malic ...
Continue ReadingJanuary 15, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows ...
Continue ReadingJanuary 10, 2025
Back to Main