Malicious code in schedules-oauth-itwin (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (9b2890eeaa5287766519e1ce14b6a3fd89f1fadad21d3f241d800da1af01561d) The OpenSSF Package Analysis project identified & ...

Continue Reading
GitLab 7.10 < 13.10.5 / 13.11 < 13.11.5 / 13.12 < 13.12.2 (CVE-2021-22213)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an ...

Continue Reading
GitLab 14.1 < 14.1.2 (CVE-2021-22236)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect ...

Continue Reading
Malware Leveraging Google OAuth for Persistent Account Access

Summary: Information-stealing malware is actively exploiting an undisclosed Google OAuth endpoint called MultiLogin. This technique was initially disclosed by a threat actor named PRISMA on their Tele ...

Continue Reading
Improper Authentication

omniauth-microsoft_graph is vulnerable to Improper Authentication. The vulnerability is due to missing validation of the email attribute received from Microsoft's OAuth service. This allows an at ...

Continue Reading
Improper Authentication

omniauth-microsoft_graph is vulnerable to Improper Authentication. The vulnerability is due to missing validation of the email attribute received from Microsoft's OAuth service. This allows an at ...

Continue Reading
GitLab 0.0 < 15.5.7 / 15.6 < 15.6.4 / 15.7 < 15.7.2 (CVE-2022-4037)

The version of GitLab installed on the remote host is affected by a vulnerability, as follows: An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting ...

Continue Reading
5 Ways to Reduce SaaS Security Risks

As technology adoption has shifted to be employee-led, just in time, and from any location or device, IT and security teams have found themselves contending with an ever-sprawling SaaS attack surface, ...

Continue Reading

Back to Main

Subscribe for the latest news: