Tim McLean discovered that pyjwt, a Python implementation of JSON Web
Token, would try to verify an HMAC signature using an RSA or ECDSA public
key as secret. This could allow remote attackers to trick applications
expecting tokens signed with asymmetric keys, into accepting arbitrary
tokens. For more information see: https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/.
Monthly Archives: June 2015
IBM Domino Web Server Cross-site Scripting Vulnerability (CVE-2015-1981)
Posted by MustLive on Jun 20
Hello list!
Earlier I wrote about XSS vulnerability in IBM Domino
(http://seclists.org/fulldisclosure/2015/May/128). I informed IBM in May
about it and at 17.06.2015 they fixed it and released security bulletin.
Security Bulletin: IBM Domino Web Server Cross-site Scripting Vulnerability
(CVE-2015-1981) http://www-01.ibm.com/support/docview.wss?uid=swg21959908.
CVE ID: CVE-2015-1981.
————————-
Affected products:…
Trio of Vulnerabilities Patched in Magneto Web App
A trio of vulnerabilities were recently patched in eBay’s Magento e-commerce web application that could have let attackers carry out a handful of exploits.