DoS in KubeEdge’s Websocket Client in package Viaduct

### Impact A large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of the response is being read into memory which could allow an attacker to send a r ...

Continue Reading
CVE-2022-31080

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by ...

Continue Reading
DoS in KubeEdge’s Websocket Client in package Viaduct

### Impact A large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of the response is being read into memory which could allow an attacker to send a r ...

Continue Reading
Internet Bug Bounty: Controllable read beyond bounds in lua_websocket_readbytes() [zhbug_httpd_126]

Greetings. I have found a read-beyond-bounds bug in lua_websocket_readbytes() that permits an attacker to exfiltrate a controllable amount of heap data if the victim site runs a suitable LUA program. ...

Continue Reading
Node.js — July 7th 2022 Security Releases

Node.js reports: HTTP Request Smuggling - Flawed Parsing of Transfer-Encoding (Medium)(CVE-2022-32213) The llhttp parser in the http module does not correctly parse and validate Transfer-Encodin ...

Continue Reading
Apache Tomcat vulnerability CVE-2022-25762

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that ...

Continue Reading
[SECURITY] Fedora 36 Update: golang-github-gobwas-ws-1.1.0-3.fc36

Tiny WebSocket library for Go.Read More ...

Continue Reading
user can get document content even after removed

# Description Admin can add a member to his personal collection .But if admin removed that user from this collection then that user still can see realtime document update content. # Proof of Concept ...

Continue Reading

Back to Main

Subscribe for the latest news: