A security flaw has been identified in MLflow, a tool used to manage machine learning workflows that some users run on their hosting accounts. This is a server-side request forgery (SSRF) vulnerability, a type of weakness that lets attackers trick the MLflow service into sending requests to systems that are meant to be private and inaccessible ...
Continue reading
A security flaw has been found in TrueConf Server, a video conferencing tool some hosting customers use for team and client calls. The issue is caused by missing authentication checks for a critical part of the software, meaning normal login requirements are not in place for this specific function.
An attacker who can access your server through ...
Continue reading
A security flaw has been identified in TrueConf Server, a service some users run on their hosted accounts. This is a code injection vulnerability, a type of issue that allows unauthorized parties to insert and run harmful, unapproved code on a system.To exploit this flaw, an attacker would need unauthorized network access to port 4307/TCP, the ...
Continue reading
A security vulnerability has been identified in Zimbra Collaboration Suite (ZCS), the email and team collaboration platform used by some of our hosting clients for hosted mail, contact management, and shared workspace features.This flaw is an operating system command injection issue. It can be exploited by an attacker who does not have a valid ...
Continue reading