Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27225PUBLISHED: 2021-03-01In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
CVE-2021-27132PUBLISHED: 2021-02-27SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
CVE-2021-25284PUBLISHED: 2021-02-27An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
CVE-2021-3144PUBLISHED: 2021-02-27In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
CVE-2021-3148PUBLISHED: 2021-02-27An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.
User Rank: Apprentice
3/11/2014 | 10:32:47 AM
Even as a small IT Service company we have to go through PCI compliance. Are these big companies too big that they dont have anyone who can see the big picutre? Do they perform 3rd party security audits? If so - why wasnt this found. If not - wow - they hold millions of credit card numbers and probably lots of Personal Information which must be protected - and they did nothing to think about security? Wow!