GitLab CVSS 10 File-Read Flaw Faces In-the-Wild Probes
GitLab issued patches for a critical CVSS 10.0 path traversal flaw in its repository commits API that allows unauthenticated file reads and is being actively probed in the wild.
Tag
3 results in the archive.
GitLab issued patches for a critical CVSS 10.0 path traversal flaw in its repository commits API that allows unauthenticated file reads and is being actively probed in the wild.
A critical Active Storage vulnerability in Ruby on Rails allows unauthenticated attackers to read arbitrary server files through malicious image uploads, risking exposure of sensitive data.
An Iran-linked hacker group associated with MOIS has started using a new modular command-and-control framework called Cavern to target Israeli IT providers and government organizations. This activity has been tracked by Check Point Research and highlights evolving state-sponsored cyber threats.