Source |
Bleeping Computer |
Identifiant |
2194861 |
Date de publication |
2021-01-15 05:05:05 (vue: 2021-01-15 11:05:29) |
Titre |
Undisclosed Apache Velocity XSS vulnerability impacts GOV sites |
Texte |
An undisclosed XSS vulnerability in Apache Velocity Tools can be exploited by unauthenticated attackers to target government sites, including NASA. [...] |
Notes |
|
Envoyé |
Oui |
Condensat |
apache attackers can exploited gov government impacts including nasa sites target tools unauthenticated undisclosed velocity vulnerability xss |
Tags |
Vulnerability
|
Stories |
|
Move |
|
Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2021-01-15 17:06:30 |
(Déjà vu) XSS vulnerability affects government websites (lien direct) |
An undisclosed Cross-Site Scripting (XSS) vulnerability in Apache Velocity Tools can be exploited by unauthenticated attackers to target government sites, including NASA, BleepingComputer reported today. Although 90 days have elapsed since the vulnerability was reported and patched, BleepingComputer is not aware of a formal disclosure made by the project.Security researcher Jackson Henry of the Sakura Samurai ethical hacking group […]
|
Vulnerability
|
|
★★★★
|