home-assistant/core and home-assistant-js-websocket are vulnerable to XSS attack.The vulnerability occurs due to a loophole in Websocket authentication logic. The logic utilises a `state` parameter wh ...
Continue ReadingDecember 14, 2023
Summary The runTailscalePing method of the TailscalePing class injects the hostname parameter inside a shell command, leading to a command injection and the possibility to run arbitrary commands on th ...
Continue ReadingDecember 14, 2023
The version of tomcat installed on the remote host is prior to 9.0.54-1. It is, therefore, affected by a vulnerability as referenced in the ALAS2TOMCAT9-2023-006 advisory. - The fix for bug 63362 pr ...
Continue ReadingDecember 14, 2023
[![Android Spyware and iOS Surveillanceware](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() New findings have identified connect ...
Continue ReadingDecember 14, 2023
Eclipse Jetty Canonical Repository =============================...Read More ...
Continue ReadingDecember 14, 2023
directus is vulnerable to Denial Of Service (DoS). The vulnerability exists because invalid websocket frames are not properly handled which allows an attacker to crash the application .Read More ...
Continue ReadingDecember 14, 2023
Introduction In July, the GitHub Security Lab team conducted a collaborative review of one of our favorite software pieces. While it's not uncommon for our Security Lab researchers to work togeth ...
Continue ReadingDecember 14, 2023
Eclipse Jetty Canonical Repository =============================...Read More ...
Continue ReadingDecember 14, 2023
Back to Main