Authorization Bypass

gitlab is vulnerable to Authorization Bypasses. This vulnerability occurs due to a flaw in the way that GitLab handles OAuth subscriptions. An attacker can exploit this vulnerability to generate OAuth ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Python Parsing Error Enabling Bypass CVE-2023-24329

### Overview urllib.parse is a very basic and widely used basic URL parsing function in various applications. ### Description An issue in the urllib.parse component of Python before v3.11 allows attac ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

(RHSA-2023:4623) Important: Red Hat OpenShift Service Mesh 2.2.9 security update

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * envoy: Clie ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

(RHSA-2023:4624) Important: Red Hat OpenShift Service Mesh Containers for 2.3.6 security update

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. Security Fix(es): * ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

(RHSA-2023:4623) Important: Red Hat OpenShift Service Mesh 2.2.9 security update

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * envoy: Clie ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Metasploit weekly wrap-up

## New module content (1) ### Metabase Setup Token RCE ![Metasploit weekly wrap-up](https://blog.rapid7.com/content/images/2023/08/metasploit-ascii-1-2.png) Authors: Maxwell Garrett, Shubham Shah, and ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Improper Authorization

gitlab is vulnerable to Improper Authorization. The vulnerability exists due to improper access to some particular fields through the GraphQL API which allows an attacker to perform unauthorized actio ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Request-Baskets 1.2.1 Server-Side Request Forgery

Post ContentRead More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: