Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
infosec.exchange
Four OpenDJ vulnerabilities are patched in 5.1.2. They include a CVSS 9.6 authorization bypass and an unauthenticated SSRF scoring CVSS 9.4.
#OpenDJ #SSRF #LDAP #AuthorizationBypass
https://securityonline.info/opendj-vulnerabilities-5-1-2/?utm_source=mastodon&utm_medium=jetpack_social
Jesus Michał von Gentoo 🏔 (he)
@mgorny@social.treehouse.systems
A #cat (owned by 3 cats), a nonconformist. #Gentoo developer, est. 2010. Taking care of #Python, #LLVM, #Xfce. #FreeSoftware enthusiast. #CarFree → #rail around #Poznań and western #Poland. #MADAO. #AntiCapitalism. #ActuallyAutistic + #diabetes. Random rants, silly humor. Playing with tongue, and enjoying double entendres. Follows require approval because apparently AI-bros think not refusing a follow is consent. Note: if you can read Polish, I recommend following my Polish profile instead (link in table). It includes unique content that doesn't work in English, and I boost all English content there anyway. #TootFinder
social.treehouse.systems
Zero days since 83 #Gentoo developers effectively lost push access over revoked PGP key signatures because of random #LDAP hiccup.
Yes, we have error handling. And yes, we have a safety check in case error handling didn't work and LDAP returned empty list of developers. Yet apparently that's not enough either, so now we also check if the diff between old and new lists isn't too large; you know, in case ldapsearch randomly returned a subset of developers and considered it a success.
You've seen all posts