GitHub: Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to User’s Projects in Project V2 GraphQL api
An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app i ...
Continue Reading
July 01, 2023
SoapUI 4.6.3 – Remote Code Execution
SoapUI 4.6.3 - Remote Code ExecutionRead More ...
Continue Reading
July 01, 2023
CVE-2014-1202
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.Read More ...
Continue Reading
July 01, 2023
ruby:2.7 security update
ruby
[2.7.4-137]
- Upgrade to Ruby 2.7.4.
- Fix command injection vulnerability in RDoc.
Resolves: rhbz#1986768
- Fix FTP PASV command response can cause Net::FTP to connect to arbitrary host.
Res ...
Continue Reading
July 01, 2023
(RHSA-2021:3559) Important: rh-ruby27-ruby security update
Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.
The following packages have been upgraded to a l ...
Continue Reading
July 01, 2023
Improper Control of Generation of Code (‘Code Injection’)
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.Read More ...
Continue Reading
July 01, 2023
Cobbler before 3.3.0 allows log poisoning
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.Read More ...
Continue Reading
July 01, 2023
Cobbler Remote Code Execution Vulnerability
Cobbler is a network installation server suite that is primarily used to quickly build Linux network installation environments. remote code execution vulnerability exists in versions of Cobbler prior ...
Continue Reading
July 01, 2023
(RHSA-2021:4702) Moderate: Satellite 6.10 Release
Red Hat Satellite is a systems management tool for Linux-based
infrastructure. It allows for provisioning, remote management, and
monitoring of multiple Linux deployments with a single centralized too ...
Continue Reading
July 01, 2023