Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-31826: Is this project still operated by anyone else? · Issue #121 · skyscreamer/nevado

Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.

CVE
#vulnerability#web

I have a security vulnerability that I want to report to this project, but I cannot contact the email on the official website,prompt "The system cannot find the email address [email protected] ” or "The system cannot find the email address [email protected] ”. Is there no one running it? If the developer or responsible person sees this issue, please reply, Next, we can discuss technical details regarding this vulnerability.

Kind regards

Related news

GHSA-7gm3-mwjw-j53w: Command injection in nevado-jms

Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda