CVE-2024-49214 - "QUIC in HAProxy allows opening a -RTT session with a spoofed IP address vulnerability"
Recently, a significant security vulnerability was discovered in HAProxy that could potentially allow an attacker to bypass the IP allow/block list functionality and open
CVE-2024-9487: Unauthorized Access to GitHub Enterprise Server via Improper Verification of Cryptographic Signature
A critical vulnerability, identified as CVE-2024-9487, was discovered in GitHub Enterprise Server which could allow attackers to bypass the SAML SSO authentication process. This would
CVE-2024-9623 - GitLab CE/EE Vulnerability Allows Deploy Keys to Push to an Archived Repository
A vulnerability (CVE-2024-9623) has been discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) that affects all versions from 8.16 to 17.2.
CVE-2024-9596: Unauthenticated GitLab Version Enumeration Vulnerability
A recently discovered critical vulnerability (CVE-2024-9596) has been reported in GitLab EE. All instances of the GitLab version starting from 16.6 prior to 17.
CVE-2024-3656: Keycloak's Admin REST API Allows Low-Privilege Users to Access Administrative Functionalities, Resulting in Potential Data Breaches and System Compromise
A security vulnerability (CVE-2024-3656) was recently discovered within Keycloak, an open-source Identity and Access Management (IAM) solution. This vulnerability allows low-privilege users to access certain
Episode
00:00:00
00:00:00