Home / Companies / Detectify / Blog / September 2020

September 2020 Summaries

2 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify's Crowdsource ethical hacker community has been actively contributing security updates, including zero-day research, which are integrated into their scanner every two weeks to keep it current with new vulnerabilities, features, and improvements. Although confidentiality agreements limit the public disclosure of all updates, users have immediate access to them through the tool. Recent security vulnerabilities reported and addressed include directory listing exposure in the WordPress Plugin File Manager, authentication bypass in MobileIron Core, server-side request forgery in Netflix Hystrix Dashboard, and information disclosure in Atlassian Confluence and Jira plugins. Additionally, vulnerabilities such as remote code execution in WordPress, exposure of Google Cloud ignore files and private keys, and cross-site scripting in Oracle WebCenter have been identified, highlighting the diverse range of security issues tackled by Detectify's community.
Sep 17, 2020 428 words in the original blog post.
Detectify's Crowdsource ethical hacker community continuously provides security updates, including 0-day research, which are integrated into the Detectify scanner every two weeks. Due to confidentiality agreements, not all updates can be publicized, but they are immediately available to users. Recent vulnerabilities identified by the community include critical issues in software such as JFrog Artifactory, Eclipse Mojarra, Atlassian Jira, BitBucket, Microsoft IIS, vBulletin, NGINX, and Oracle E-Business Suite. These vulnerabilities range from authentication bypasses and directory traversal to exposed configuration files and cross-site scripting (XSS), highlighting the importance of regularly updating and securing systems to protect against potential exploits.
Sep 04, 2020 399 words in the original blog post.