Aggregator
安全419盘点 | 第三季度数据泄露事件趋势分析
1 year 8 months ago
数据泄露事件,主要涉及银行、电商、消费金融、保险、快递等多个行业。
GitLab security advisory (AV24-579)
1 year 8 months ago
Canadian Centre for Cyber Security
«Молот ведьм»: бестселлер средневековья, погубивший тысячи женщин
1 year 8 months ago
Исследователи нашли виновника трехвековой инквизиции.
RSAC解读:隐私融入,让隐私设计与安全设计共生
1 year 8 months ago
在2024年的RSA大会上,普华永道的Kim Wuyts分享了题为《隐私融入,让隐私设计与安全设计共生》的议题。她详细讨论了隐私和安全在设计层面的交集,强调隐私不仅仅是数据机密性的保障,更是对业务流程、用户体验、风险管理等方面的全方位考虑。
CVE-2021-39122 | Atlassian JIRA Server up to 8.5.12/8.13.4/8.15.0 Search Endpoint /rest/api/2/search information disclosure
1 year 8 months ago
A vulnerability was found in Atlassian JIRA Server up to 8.5.12/8.13.4/8.15.0 and classified as problematic. This issue affects some unknown processing of the file /rest/api/2/search of the component Search Endpoint. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2021-39122. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-39118 | Atlassian JIRA Server/Data Center up to 8.18.x Endpoint /rest/api/1.0/render information disclosure (JRASERVER-72736)
1 year 8 months ago
A vulnerability was found in Atlassian JIRA Server and Data Center up to 8.18.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /rest/api/1.0/render of the component Endpoint. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2021-39118. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-39123 | Atlassian JIRA Server/Data Center up to 8.15.x Endpoint generate denial of service (JRASERVER-72237)
1 year 8 months ago
A vulnerability, which was classified as problematic, has been found in Atlassian JIRA Server and Data Center up to 8.15.x. This issue affects some unknown processing of the file /rest/gadget/1.0/createdVsResolved/generate of the component Endpoint. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2021-39123. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-20827 | MediaTek MT8797 ims Service improper synchronization (ALPS07937105)
1 year 8 months ago
A vulnerability was found in MediaTek MT6761, MT6762, MT6763, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8673, MT8791T and MT8797. It has been rated as problematic. This issue affects some unknown processing of the component ims Service. The manipulation leads to improper synchronization.
The identification of this vulnerability is CVE-2023-20827. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-20828 | MediaTek MT8365 GPS out-of-bounds write (ALPS08014144)
1 year 8 months ago
A vulnerability classified as critical has been found in MediaTek MT2735, MT6761, MT6762, MT6765, MT6768, MT6769, MT6779, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6980, MT6983, MT6985, MT6990, MT8167, MT8167S, MT8168, MT8175, MT8362A and MT8365. Affected is an unknown function of the component GPS. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2023-20828. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-20829 | MediaTek MT8365 GPS out-of-bounds write (ALPS08014144)
1 year 8 months ago
A vulnerability classified as critical was found in MediaTek MT2735, MT6761, MT6762, MT6765, MT6768, MT6769, MT6779, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6980, MT6983, MT6985, MT6990, MT8167, MT8167S, MT8168, MT8175, MT8362A and MT8365. Affected by this vulnerability is an unknown functionality of the component GPS. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2023-20829. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-20830 | MediaTek MT8781 GPS out-of-bounds write (ALPS08014144)
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in MediaTek MT2713, MT2735, MT6761, MT6762, MT6765, MT6768, MT6769, MT6779, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6980, MT6983, MT6985, MT6990, MT8167, MT8167S, MT8168, MT8173, MT8195, MT8362A, MT8365 and MT8781. Affected by this issue is some unknown functionality of the component GPS. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2023-20830. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-20831 | MediaTek MT8365 GPS out-of-bounds write (ALPS08014144)
1 year 8 months ago
A vulnerability, which was classified as critical, was found in MediaTek MT2735, MT6761, MT6762, MT6765, MT6768, MT6769, MT6779, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6980, MT6983, MT6985, MT6990, MT8167, MT8167S, MT8175, MT8195, MT8362A and MT8365. This affects an unknown part of the component GPS. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2023-20831. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-4612 | Apereo Foundation CAS up to 7.0.0-RC7 Multi-Factor Authentication improper authentication
1 year 8 months ago
A vulnerability has been found in Apereo Foundation CAS up to 7.0.0-RC7 and classified as critical. This vulnerability affects unknown code of the component Multi-Factor Authentication. The manipulation leads to improper authentication.
This vulnerability was named CVE-2023-4612. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-6998 | CoolKit Technology eWeLink Smart Home up to 5.1.x on Android/iOS privileges management
1 year 8 months ago
A vulnerability classified as critical has been found in CoolKit Technology eWeLink Smart Home up to 5.1.x on Android/iOS. This affects an unknown part. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2023-6998. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-6551 | class.upload.php unrestricted upload
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in class.upload.php. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2023-6551. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-49256 | Hongdian H8951-4G-ESP prior 2310271149 Configuration Backup hard-coded credentials
1 year 8 months ago
A vulnerability was found in Hongdian H8951-4G-ESP and classified as critical. Affected by this issue is some unknown functionality of the component Configuration Backup Handler. The manipulation leads to hard-coded credentials.
This vulnerability is handled as CVE-2023-49256. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Randall Munroe’s XKCD ‘CIDABM’
1 year 8 months ago
via the comic humor & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘CIDABM’ appeared first on Security Boulevard.
Marc Handelman
Reshape IT Operations with AIOps
1 year 8 months ago
Artificial intelligence (AI) is reshaping the modern business landscape, much like steam and steel shaped the industrial revolutions. Instead of revolutionizing manufacturing processes, AI is transforming IT operations thanks to automation and streamlined processes. Artificial intelligence for IT operations (AIOps)...
NETSCOUT
Walking the Tightrope Between Innovation & Risk
1 year 8 months ago
When employees and leaders engage with CISOs early in innovation projects, security concerns are addressed proactively, building trust and ensuring innovation and security coexist.
Jill Knesek