Security Updates for Azure CycleCloud (Nov 2022)

The Azure CycleCloud product is missing security updates. It is, therefore, affected by an elevation of privilege vulnerability. An unauthenticated, adjacent attacker can exploit this, via brute force ...

Continue Reading

CVSS3 - HIGH

(RHSA-2023:0466) Important: Red Hat OpenShift GitOps security update

Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications. Security Fix(es): * ArgoCD: JWT audience claim is not verified (CVE-2023-22482) For more ...

Continue Reading

CVSS3 - CRITICAL

(RHSA-2023:0467) Important: Red Hat OpenShift GitOps security update

Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications. Security Fix(es): * ArgoCD: JWT audience claim is not verified (CVE-2023-22482) * ArgoCD ...

Continue Reading

CVSS3 - CRITICAL

(RHSA-2023:0468) Important: Red Hat OpenShift GitOps security update

Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications. Security Fix(es): * ArgoCD: JWT audience claim is not verified (CVE-2023-22482) For more ...

Continue Reading

CVSS3 - CRITICAL

Amazon Linux 2022 : (ALAS2022-2023-274)

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2022-2023-274 advisory. - Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalati ...

Continue Reading

CVSS3 - HIGH

Security Bulletin: Vulnerability in GraphQL Java may affect IBM Robotic Process Automation and result in a denial of service (CVE-2022-37734)

## Summary There is a vulnerability in the Java used by IBM Robotic Process Automation as part of it's infrastructure, license management and UMS which may result in a denial of service. (CVE-2022-377 ...

Continue Reading

CVSS3 - HIGH

Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects

### Impact This issue affects Rancher versions from 2.5.0 up to and including 2.5.16, from 2.6.0 up to and including 2.6.9 and 2.7.0. It was discovered that the security advisory CVE-2021-36782 (GHSA- ...

Continue Reading

CVSS3 - CRITICAL

Rancher cattle-token is predictable

### Impact An issue was discovered in Rancher versions up to and including 2.6.9 and 2.7.0, where the `cattle-token` secret, used by the `cattle-cluster-agent`, is predictable. Even after the token is ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: