Improper Validation of Certificate with Host Mismatch in mellium.im/xmpp/websocket

If no TLS configuration is provided by the user, the websocket package constructs its own TLS configuration using recommended defaults.Read More ...

Continue Reading
nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate

The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which a ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-23602

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from insi ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Apache Tomcat Request Obfuscation Vulnerability

Apache Tomcat is a lightweight Web application server from the Apache Foundation. The application implements support for Servlet and JavaServer Page (JSP).Apache Tomcat suffers from a request obfuscat ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate

The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which a ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

July 7th 2022 Security Releases

# July 7th 2022 Security Releases By Rafael Gonzaga, 2022-07-07 ## _(Update 07-July-2022)_ Security releases available Updates are now available for the v18.x, v16.x, and v14.x Node.js release lines f ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Nutanix AOS : Multiple Vulnerabilities (NXSA-AOS-5.20.4.5)

The version of AOS installed on the remote host is prior to 5.20.4.5. It is, therefore, affected by multiple vulnerabilities as referenced in the NXSA-AOS-5.20.4.5 advisory. - zlib before 1.2.12 all ...

Continue Reading
Amazon Web Services EC2 instance enumeration

Provided AWS credentials, this module will call the authenticated API of Amazon Web Services to list all SSM-enabled EC2 instances accessible to the account. Once enumerated as SSM-enabled, the instan ...

Continue Reading

Back to Main

Subscribe for the latest news: