Company
Date Published
Author
Detectify
Word count
318
Language
-
Hacker News points
None

Summary

Detectify's Crowdsource ethical hacker community has been actively contributing security updates, including critical 0-day research, leading to rapid deployment of tests for Asset Monitoring within 25 minutes from detection to scanner. Despite confidentiality agreements preventing the public disclosure of all updates, these vulnerabilities are immediately integrated into the Detectify scanner. Notable vulnerabilities identified between November 16 and November 27 include CVE-2020-14815, which exploits a DOM XSS flaw in Oracle Business Intelligence Enterprise Edition, CVE-2020-8209, involving path traversal in Citrix XenMobile Server, and CVE-2020-4782, concerning directory traversal in IBM WebSphere Application Server. In anticipation of increased e-commerce activity during Black Friday and Cyber Monday, the team prioritized vulnerabilities in e-commerce technologies like Modified eCommerce, OXID eShop, Magento, ECShop, and JTL-Shop, ranging from installer disclosures to remote code executions. Additionally, numerous vulnerabilities in Atlassian Jira apps were reported, including issues with improper access control and remote code execution.