RHEL 8 : OpenShift Container Platform 4.9.56 (RHSA-2023:0777)

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:0777 advisory. google-oauth-client: missing PKCE support ...

Continue Reading
openSUSE: Security Advisory for roundcubemail (openSUSE-SU-2023:0285-1)

The remote host is missing an update for...Read More ...

Continue Reading
Wallarm’s Open Source API Firewall debuts at Blackhat Asia 2024 – Introduces Key New Features & Functionalities

Wallarm introduced its ongoing Open Source API Firewall project to the world at the recently concluded Blackhat Asia 2024 conference in Singapore. The open-source API Firewall by Wallarm is a free, li ...

Continue Reading
OAuth Server < 4.4.0 – Open Redirect

Description The WP OAuth Server (OAuth Authentication) plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.3.3. This is due to insufficient validation on a redi ...

Continue Reading
OAuth Server < 4.4.0 – Open Redirect

Description The WP OAuth Server (OAuth Authentication) plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.3.3. This is due to insufficient validation on a redi ...

Continue Reading
Security Bulletin: IBM Sterling B2B Integrator B2B API vulnerable to multiple issues due to Apache CXF

Summary IBM Sterling B2B Integrator uses Apache CXF. This bulletin identifies the steps to take to address the vulnerabilities. Vulnerability Details ** CVEID: CVE-2022-46363 DESCRIPTION: **Apache CX ...

Continue Reading
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 1, 2024 to April 7, 2024)

Did you know we're running a Bug Bounty Extravaganza again? Earn over 6x our usual bounty rates, up to $10,000, for all vulnerabilities submitted through May 27th, 2024 when you opt to have Wordf ...

Continue Reading
google-oauth-java-client improperly verifies cryptographic signature

Summary The vulnerability impacts only users of the IdTokenVerifier class. The verify method in IdTokenVerifier does not validate the signature before verifying the claims (e.g., iss, aud, etc.). Sign ...

Continue Reading

Back to Main

Subscribe for the latest news: