Searching in Data Privacy & Cybersecurity · Search everything
702 changes Data Privacy & Cybersecurity
Atlassian Bamboo Data Center Vulnerability Allows Code Execution
CERT-Bund has issued a security advisory regarding a vulnerability in Atlassian Bamboo Data Center versions prior to 9.6.24, 10.2.16, and 12.1.3. The vulnerability allows remote, authenticated attackers to execute arbitrary code, posing a high risk.
Langflow Vulnerability Allows Remote Code Execution
CERT-Bund has issued a security advisory for Langflow, detailing a critical vulnerability that allows remote code execution. The advisory affects versions prior to 1.9.0 and impacts Linux, UNIX, and Windows operating systems. Mitigation measures are available.
Oracle Fusion Middleware Vulnerability Allows Code Execution
CERT-Bund has issued a security advisory for Oracle Fusion Middleware Identity Manager and Web Services Manager versions prior to 12.2.1.4.0 and 14.1.2.1.0. A critical vulnerability (CVSS 9.8) allows remote attackers to execute arbitrary code, potentially leading to full system compromise.
Kubernetes ingress-nginx Vulnerability Allows Code Execution and Info Disclosure
CERT-Bund has issued a security advisory for Kubernetes ingress-nginx, detailing a vulnerability that allows authenticated remote attackers to execute arbitrary code and disclose sensitive information. The advisory affects versions prior to 1.13.9, 1.14.5, and 1.15.1, with a high CVSS base score of 8.8.
VMware Tanzu Spring Boot Actuator Vulnerabilities
CERT-Bund has issued a security advisory for VMware Tanzu Spring Boot Actuator, detailing vulnerabilities that allow remote attackers to bypass security measures. The advisory affects multiple versions of VMware Tanzu Spring Boot prior to specific patch levels and includes a high CVSS base score.
Microsoft 365 Copilot Vulnerabilities Advisory
CERT-Bund has issued an advisory regarding multiple vulnerabilities in Microsoft 365 Copilot, with a CVSS base score of 8.9. These vulnerabilities could allow remote attackers to disclose information, manipulate data, and gain elevated privileges. Mitigation measures are available.
VMware Tanzu Spring Security Vulnerability
CERT-Bund has issued a security advisory for VMware Tanzu Spring Security, detailing a critical vulnerability (CVSS 9.1) that allows remote attackers to bypass security controls and potentially access confidential information. The advisory affects multiple versions of the Spring Security framework.
Netwrix Password Secure Vulnerabilities Allow Code Execution and DoS
CERT-Bund has issued a security advisory for Netwrix Password Secure, detailing multiple vulnerabilities that could allow for code execution and denial-of-service attacks. The advisory affects versions prior to 26.3.100 and is rated as high severity.
Critical Azure Vulnerabilities: Remote Attack, Privilege Escalation
CERT-Bund has issued a security advisory regarding critical vulnerabilities in Microsoft Azure DevOps, Data Factory, and Cloud Shell. These vulnerabilities allow remote attackers to escalate privileges, manipulate data, and disclose sensitive information, with a CVSS base score of 10.0.
Google Chrome Vulnerabilities (CVSS 8.8)
CERT-Bund has issued a security advisory for Google Chrome, detailing multiple vulnerabilities with a CVSS Base Score of 8.8. These vulnerabilities could allow remote attackers to execute code, bypass security measures, cause denial-of-service, or manipulate data. Affected versions include Google Chrome prior to 146.0.7680.153 and 146.0.7680.154 on Linux, MacOS X, and Windows.