What are JWT Injections, and Why do You Need to Know About Them

JSON Web Tokens (JWTs for short) are the new standard for transmitting identity information in the digital age. JWTs are JSON objects that act as an identifier for your user or application. They’re u ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

What are JWT Injections, and Why do You Need to Know About Them

JSON Web Tokens (JWTs for short) are the new standard for transmitting identity information in the digital age. JWTs are JSON objects that act as an identifier for your user or application. They’re u ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Path Traversal

gravitee-gateway-core is vulnerable to path traversal. The vulnerability exists due to the lack of dynamic routing checks in the `selectUserDefinedEndpoint` function of `TargetEndpointResolver.java`, ...

Continue Reading

CVSS3 - MEDIUM

Updated libgsasl packages fix security vulnerability

GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client. (CVE-2022-2469)Read More ...

Continue Reading

CVSS3 - HIGH

Security Bulletin: Apache Log4j Vulnerability Affects IBM Sterling Transformation Extender (CVE-2021-44228)

## Summary IBM Sterling Transformation Extender is impacted by Log4j2 security vulnerability, CVE-2021-44228, where an attacker can control log messages or log message parameters can execute arbitrary ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

dotCMS Unrestricted Upload of File Vulnerability

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage l ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

php:7.4 security update

php [7.4.19-4] - fix uninitialized array in pg_query_params() leading to RCE CVE-2022-31625Read More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

php:7.4 security update

php [7.4.19-4] - fix uninitialized array in pg_query_params() leading to RCE CVE-2022-31625Read More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: