Don’t Let API Leaks Sink Your Ship | API Security Newsletter

Leaks of API keys and other secrets. The industry has been abuzz with news about attacks – and the ongoing ripple effect – involving leaked API keys, credentials and other secrets. This adds ...

Continue Reading

CVSS3 - CRITICAL

Don’t Let API Leaks Sink Your Ship | API Security Newsletter

Leaks of API keys and other secrets. The industry has been abuzz with news about attacks – and the ongoing ripple effect – involving leaked API keys, credentials and other secrets. This adds ...

Continue Reading

CVSS3 - CRITICAL

Security Bulletin: IBM MQ is affected by FasterXML jackson-databind vulnerabilities (CVE-2022-42003, CVE-2022-42004)

## Summary Multiple issues were identified with the Jackson library that is used within the IBM MQ Console to provide REST API functionality. ## Vulnerability Details **CVEID: **[CVE-2022-42003]() ** ...

Continue Reading

CVSS3 - HIGH

Fedora 36 : git-credential-oauth (2023-2663dc67d8)

The remote Fedora 36 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2023-2663dc67d8 advisory. - An attacker can cause excessive memory growth in a Go se ...

Continue Reading

CVSS3 - MEDIUM

Fedora 37 : git-credential-oauth (2023-267503a090)

The remote Fedora 37 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2023-267503a090 advisory. - An attacker can cause excessive memory growth in a Go se ...

Continue Reading

CVSS3 - MEDIUM

Security Bulletin: IBM WebSphere Application Server Liberty for IBM i is vulnerable to HTTP header injection and affected by denial of services due to multiple vulnerabilities.

## Summary IBM WebSphere Application Server Liberty for IBM i is vulnerable to an HTTP header injection caused by improper validation, and affected by a denial of service in GraphQL Java, a denial of ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Exploit for Command Injection in Atlassian Bitbucket

# Atlassian-Bitbucket-Server-CVE-2022-36804 A critical command ...Read More ...

Continue Reading

CVSS3 - HIGH

CVE-2023-22374: F5 BIG-IP Format String Vulnerability

![CVE-2023-22374: F5 BIG-IP Format String Vulnerability](https://blog.rapid7.com/content/images/2023/02/GettyImages-1352385622.jpg) While following up our [previous work on F5's BIG-IP devices](), Rap ...

Continue Reading

CVSS3 - HIGH

Back to Main

Subscribe for the latest news: