Home / Companies / Detectify / Blog / March 2021

March 2021 Summaries

3 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify's Crowdsource ethical hacker community has been actively contributing security updates, including zero-day research, to enhance the platform's Surface Monitoring capabilities, which now deliver tests within 25 minutes from identification to deployment. While confidentiality agreements prevent the public disclosure of all security updates, new tests are promptly integrated into the Detectify scanner and are accessible to users. Recent vulnerabilities reported and addressed include a deserialization flaw in Onedev allowing remote code execution, an access token leak in Onedev, and cross-site scripting (XSS) vulnerabilities in Jenzabar, Adminer, and hello.js, which could enable attackers to execute unauthorized JavaScript or steal credentials. These vulnerabilities were submitted by ethical hackers payloadartist, xelkomy, and madrobot, showcasing the collaborative efforts of the community in identifying and mitigating security threats.
Mar 23, 2021 318 words in the original blog post.
Detectify's Crowdsource community of ethical hackers has reported a series of critical security vulnerabilities, which have been swiftly integrated into their asset monitoring scanner. Notable vulnerabilities include a server-side request forgery (SSRF) in Microsoft Exchange (CVE-2021-26855) that could allow remote code execution (RCE) by exploiting multiple flaws, and a remote code execution (RCE) issue in VMware vCenter's HTML5 client (CVE-2021-21973), both carrying critical threat levels. Other significant vulnerabilities include reflected cross-site scripting (XSS) in Palo Alto Networks PAN-OS, SQL injection in phpMyAdmin versions prior to 4.9.6 and 5.0.3, and an arbitrary file upload flaw in Apache Flink. Apache NiFi also faces an RCE vulnerability, while Cisco UCS Director and Express for Big Data have a local file inclusion (LFI) flaw. Additionally, the Grandstream UCM6200 series is susceptible to remote SQL injection, and PrestaShop Opart devis versions below 4.0.2 contain an Insecure Direct Object Reference (IDOR) vulnerability. These vulnerabilities underscore the importance of timely updates and patches to protect systems from potential exploits.
Mar 08, 2021 498 words in the original blog post.
Detectify has enhanced its Dynamic Application Security Testing (DAST) scanner with a new fuzzing engine to mimic the behavior of an automated hacker, enabling the discovery of more challenging security vulnerabilities. This advancement allows the scanner, called Deep Scan, to go beyond static testing by employing an enhanced black-box testing approach that identifies vulnerabilities not typically found by conventional scanners. The revamped fuzzing engine enables the detection of new vulnerability classes and has already led to an increase in medium and high-severity vulnerability findings for customers. By improving the ability to detect these critical vulnerabilities, the new engine not only saves time and resources for users but also contributes to the broader mission of making the internet more secure. Detectify encourages users to explore this new capability through a demo or trial, offering them the opportunity to identify previously undetectable vulnerabilities in their web applications.
Mar 04, 2021 554 words in the original blog post.