New Alerts for CPython, Microsoft GitHub, Jira, Bosch, Mitel, and Linux.
CPython
A vulnerability in the parse_cookie function could be exploited by sending specially crafted cookie values to trigger significant delays, resulting in a DoS. CVSSv3 score of 7.5
More info. And here.
GitHub Enterprise Server has been patched to fix 3 vulnerabilities, one of which exposed signed federation metadata XML, allowing a remote attacker to forge a SAML response to provision and/or gain access to a user account with site administrator privileges. Highest CVSSv4 score of 9.5
More info.
Reflected XSS and CSRF vulnerabilities exist in Confluence Data Center and Server. CVSSv3 score of 7.1
More info.
A vulnerability in Bosch IP cameras of families CPP13 and CPP14, allows a remote attacker to retrieve video analytics event data. CVSSv3 score of 7.5
More info.
An unauthorized access vulnerability exists in the Legacy Chat component of Mitel MiContact Center Business, which could allow a remote attacker to access sensitive information and send unauthorized messages. CVSSv3 score of 8.1
More info. And here.
SUSE has updated the kernel firmware. More info.
Red Hat has updated the kernel. More info.
Comments