FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

CISA Flags 6 Vulnerabilities - Apple, Apache, Adobe, D-Link, Joomla Under Attack

By: Newsroom β€” January 10th 2024 at 04:50
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This includes CVE-2023-27524 (CVSS score: 8.9), a high-severity vulnerability impacting the Apache Superset open-source data visualization software that could enable remote code execution.
☐ β˜† βœ‡ The Hacker News

Alert: Apache Superset Vulnerabilities Expose Servers to Remote Code Execution Attacks

By: THN β€” September 7th 2023 at 11:02
Patches have been released to address two new securityΒ vulnerabilities in Apache SupersetΒ that could be exploited by an attacker to gain remote code execution on affected systems. The update (version 2.1.1) plugsΒ CVE-2023-39265Β andΒ CVE-2023-37941, which make it possible to conduct nefarious actions once a bad actor is able to gain control of Superset’s metadata database. Outside of these
☐ β˜† βœ‡ The Hacker News

Apache Superset Vulnerability: Insecure Default Configuration Exposes Servers to RCE Attacks

By: Ravie Lakshmanan β€” April 26th 2023 at 09:29
The maintainers of theΒ Apache SupersetΒ open source data visualization software have released fixes to plug an insecure default configuration that could lead to remote code execution. The vulnerability, tracked asΒ CVE-2023-27524Β (CVSS score: 8.9), impacts versions up to and including 2.0.1 and relates to the use of a default SECRET_KEY that could be abused by attackers to authenticate and access
❌