Two critical RabbitMQ flaws allow authentication bypass. One forges TLS client certs; the other tricks OAuth2 JWKS to accept any JWT.
#RabbitMQ #AuthBypass #TLS #OAuth2 #InfoSec
https://securityonline.info/rabbitmq-authentication-bypass-flaws/?utm_source=mastodon&utm_medium=jetpack_social
About This Hashtag
#oauth2
4 posts
Last used Jul 15
#oauth2
4 posts· Last used Jul 15
SAP Commerce Cloud impacted by CRITICAL CVE-2026-44761 (CVSS 9.1): Default OAuth2 credentials can let unauthenticated attackers access APIs & modify data. Change/remove sample creds now. No patch yet. https://radar.offseq.com/threat/cve-2026-44761-cwe-1392-use-of-default-credentials-009b0a23096bbf37 #OffSeq #SAP #OAuth2 #Vuln
Fun setting up OAuth2 for my local @forgejo@floss.social with no hassle.
cc: @jerry@infosec.exchange
#OAuth2 #Forgejo
You've seen all posts