Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-43623

A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.3), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.3), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.4.0). Applications using the affected module are vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a brute force attack with valid users.

CVE
#vulnerability#pdf#auth

%PDF-1.5 %���� 55 0 obj << /Length 2572 /Filter /FlateDecode >> stream x��ZYs�8~����JU#7�Ծh|�<’YK��Tf��Y��({��o7J$E1tI٩JL}}�͆h����ٯ��kG�X�u4~� %�֑��(f��4��e�<]��n��(�lV�S�,��N_��텡o}���,��ZN7�������?ǿ�]���}ƀ!��������4�»�"J���W7sI%���g���g4U\+4Q<�4�1o�Kb�ܒt�Q,b�XiLYA��㠠�p����x�/S�0�esf`b�ݼD�0b��BC0"c�&3�Pj�ܯ��>�rb@]x��Ǣ�w�8Q�s�+�⸍w$3S��j�g�����$ϖ�1�!�r��Pl�I A��mb 1��_���-@�o� ��’����>��RسP�ƶ ��$��!k0�D/��A�9�;�@�D�v΁��5ܦ�i�������qÛNa@J"�<В5�_C�����c���Kն��XUb�%�IN��~��˓�x�����iC0��+Pd��!,崓4fZ� ���5qn!E�R�|=�Բ�@���р+"� �ظ�7�&>��w���;H���=��b�(��-��1b���?$�ܯ���U�0��U��*]��_�1���5���qY� #�뾌F~ы �����Ӑ�’�2`���:��U����J6�% �Ķ�XZBu�����vx�W��;n^�>��w�(�xA�a�x��O �ж�����s �0q��ֹ. �bY�����{���,y�a �O��l0g�]o3^��qʋ��n0�t7�?%�_9Ynfa�d6[z�GE�ZY��$�i/`���}�;�Af�h��_Wi��������Y6��(��.�.Bl\�UY�‚�uW�i�{J܍��f)���o��9}�0"����7ɃO’y��ٗ��`�ët��Î�@�ɷ��O.ƶ�g�}�_z�vR6�������E?V�ޏ���W�ˆ��-xl�����1r�Hh(#kc�a�R����ק����A �N|��_R�.$�$��V��6�f�� ��J���\8v�8�T�1��$� �O��7�>6�,�?)�\V�w�VW���` 쟆� h��-$`r 4t�bG�����]�>Y�-o���+����Xh��mkG��$�!! Ax.�Bu �"?�#�˫ʅY�!>�4i����ۘ0��U���MdU#wާفO)>j�xx���^���?�s�����=g�(���e�V{&���%��\�����o�9����/�axWs��?����_ >�A|]��$�� ������]�u�v���f��Ȋn����A���+<���O�����5w_��R-xr��P�`�_���FFQ#�u�⢯����J��@�ue�S�?�ߝ��_5��*�%��U sg�8�e���h�����J�&� �P���)��,�k�՛5���-1���ci ��A�)@%��0�U�W� <��N���{�U׈*�ԩQ%�󟟃*�%�y�ެ�}H0�2�yG��H+�!�2��� �dvJXٿV�H��h��)4����a�:1�D�aY�X p ��[`�v��AB��h{��!������P�ry�s�{&aB��`�N("��Fa��0V ��F{���b�-c;1-����’�� ����B��g��5sr�!~�~�ެ�}��’}Ԏ��;l��k���i+;t�88��{ǿ\���C߫��x�Ԫ�x:Ӆ���*- O�.$:t���Ҧ*Hc�����Gq�ze](��������+l�ތo�����[5j�֣��j_�+�r��B�e�`��N�?(哢���G��d�H�gy��{�G��3��8�ઙM����k�&��u:�[��W��Gf�"���Zh��mJ�<�A2�����L�ew��2ϻ���vߧ�9����4�FzPY��mq�����t7! �� h. ���W������^�]v>����:�H�򎴤��>�������VN4(��y�M~ƀ���5+e�����O��Wm��on�M h 3�

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907