JeecgBoot JimuReport FreeMarker SSTI RCE – CVE-2023-4450

Vulnerable Version version prior to 1.6.0 Fixed Version UPdate latest Versions Base Score 9.8 critical                                                                   Vendor Discription:- JeecgBoot is a Spring Boot–based low-code platformContinue readingJeecgBoot JimuReport FreeMarker SSTI RCE – CVE-2023-4450

Apache Superset Hardcoded JWT Secret Key Leads to Authentication Bypass – CVE-2023-27524

Vulnerable Version versions =<2.0.1 Fixed Version Update latest version Base Score 9.8 CRITICAL                                                                   Vendor Description:- Apache Superset is an open-source data visualization and explorationContinue readingApache Superset Hardcoded JWT Secret Key Leads to Authentication Bypass – CVE-2023-27524

CraftCMS ConditionsController Pre-Auth RCE – CVE-2023-41892

Vulnerable Version versions 4.0.0-RC1 to 4.4.14 Fixed Version version 4.4.15 Base Score 9.8 CRITICAL                                                                   Vendor Description:- Craft CMS (Content Management System) is a flexibleContinue readingCraftCMS ConditionsController Pre-Auth RCE – CVE-2023-41892