Russian Election Interference: What’s Next?

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2020-17366
PUBLISHED: 2020-08-05

An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate…

CVE-2020-9036
PUBLISHED: 2020-08-05

Jeedom through 4.0.38 allows XSS.

CVE-2020-15127
PUBLISHED: 2020-08-05

In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy’s shutdown procedure. The shutdown procedure includes flip…

CVE-2020-15132
PUBLISHED: 2020-08-05

In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given string is not found, a response with a `400` error code is returned, along with a error message saying that th…

CVE-2020-7298
PUBLISHED: 2020-08-05

Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.

Read More HERE

Leave a Reply