A security flaw has been identified in Microsoft SharePoint, a common tool many website owners use to build team collaboration spaces, share files, and manage custom hosted site features.The issue is a weak authentication vulnerability, meaning the system’s built-in check to confirm only approved users can access protected parts of a SharePoint ...
Continue reading
A security flaw has been identified in Broadcom VMware vCenter, a tool commonly used to manage virtual server hosting environments. This is a path traversal vulnerability, a type of weakness that lets an unauthorized party access protected parts of the system they would not normally be able to reach.
If a bad actor has access to the network your ...
Continue reading
A security vulnerability has been identified in Microsoft's Internet Key Exchange (IKE) Service Extensions, a component used to manage secure network connections for devices and online services. The flaw stems from a coding error called a "double free," which occurs when a system accidentally tries to free the same block of computer memory twice, ...
Continue reading
A security flaw has been found in MLflow, a tool used to manage machine learning projects and related workflows. This flaw is a server-side request forgery (SSRF) vulnerability, meaning attackers can trick the MLflow service into sending unauthorized requests on its own behalf.This vulnerability lets bad actors use an affected MLflow instance to ...
Continue reading