Tag: KubernetesSecurity

  • Vulnerability Watch No53

    Kubernetes managed-serviceaccount flaw exposes cluster secrets • OpenSearch Dashboards request flaw enables remote denial of service • Dell PowerStore SDNAS NFS flaw can enable command execution • RabbitMQ Java client nesting bug triggers pre-authentication crashes • RabbitMQ Java client flaw enables massive pre-auth memory allocation…

  • Vulnerability Watch No42

    UpSnap Fresh Installs Exposed to Unauthenticated Root RCE • Cedar Express Middleware Flaw Can Bypass Route Authorization • MRBS Vulnerable to Server-Side Request Forgery • OpenStack Designate Flaw Enables Cross-Tenant DNS Hijacking • UpSnap Device Fields Allow Authenticated Command Injection…

  • Vulnerability Watch No23

    Hashi Vault JS Flaw Enables Path and Query Injection • Defaults Deep Library Vulnerable to Prototype Pollution • DSSRF DNS Handling Bug Reopens SSRF Paths • Vault Webhook Flaw Can Leak Kubernetes Service Account Tokens • cPanel Database Rename Flaw Enables Root-Context SQL Execution…