Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
217

Oracle Linux 9 ELSA-2024-4165 High: Token Bypass in pki-core

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4165 http://linux.oracle.com/errata/ELSA-2024-4165.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: idm-pki-acme-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-base-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-ca-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-est-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-java-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-kra-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-server-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-tools-11.5.0-2.0.1.el9_4.x86_64.rpm python3-idm-pki-11.5.0-2.0.1.el9_4.noarch.rpm aarch64: idm-pki-acme-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-base-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-ca-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-est-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-java-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-kra-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-server-11.5.0-2.0.1.el9_4.noarch.rpm idm-pki-tools-11.5.0-2.0.1.el9_4.aarch64.rpm python3-idm-pki-11.5.0-2.0.1.el9_4.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//pki-core-11.5.0-2.0.1.el9_4.src.rpm Related CVEs: CVE-2023-4727 Description of changes: [11.5.0-2.0.1] - Replaced upstream graphical references [Orabug: 33952704] [11.5.0-2] - RHEL-9916 CVE-2023-4727 pki-core: dogtag ca: token authentication bypass vulnerability _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The ELSA-2024-4165 advisory for Oracle Linux tackles vulnerabilities in token authentication circumvention within the pki-core package, detailing the impact and severity. Oracle Linux, ELSA-2024-4165, pki-core, security advisory, authentication issue. . LinuxSecurity.com Team

Calendar%202 Jun 28, 2024 Oracle
89

Fedora 22: 214117 Critical: python-jwt Token Verification Bypass

Latest upstream with security fix for https://seclists.org/oss-sec/2015/q2/3 https://github.com/jpadilla/pyjwt/commit/88a9fc56bdc6c870aa6af93bda401414a217db2a. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-10350 2015-06-20 13:45:56 -------------------------------------------------------------------------------- Name : python-jwt Product : Fedora 22 Version : 1.3.0 Release : 1.fc22 URL : https://pypi.org/project/PyJWT/ Summary : JSON Web Token implementation in Python Description : A Python implementation of JSON Web Token draft 01. This library provides a means of representing signed content using JSON data structures, including claims to be transferred between two parties encoded as digitally signed and encrypted JSON objects. -------------------------------------------------------------------------------- Update Information: Latest upstream with security fix for https://seclists.org/oss-sec/2015/q2/3 https://github.com/jpadilla/pyjwt/commit/88a9fc56bdc6c870aa6af93bda401414a217db2a -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2015 Ralph Bean - 1.3.0-1 - new version - start running the test suite. * Fri Mar 27 2015 Ralph Bean - 1.0.1-1 - new version * Thu Mar 19 2015 Ralph Bean - 1.0.0-1 - new version -------------------------------------------------------------------------------- References: [ 1 ] Bug #1231173 - python-jwt: token verification bypass with "none" algorithm https://bugzilla.redhat.com/show_bug.cgi?id=1231173 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update python-jwt' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . A recent patch for python-jwt in Fedora 22 addresses serious security vulnerabilities, improving token validation to enhance protection against threats. python-jwt Security Update,Fedora 22 Update,JSON Web Token Fix,Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 30, 2015 Critical Fedora
89

Fedora 21 FEDORA-2015-10249 Critical: Python-JWT Token Bypass Issue

Latest upstream with security fix for https://seclists.org/oss-sec/2015/q2/3 https://github.com/jpadilla/pyjwt/commit/88a9fc56bdc6c870aa6af93bda401414a217db2a. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-10249 2015-06-20 13:38:05 -------------------------------------------------------------------------------- Name : python-jwt Product : Fedora 21 Version : 1.3.0 Release : 1.fc21 URL : https://pypi.org/project/PyJWT/ Summary : JSON Web Token implementation in Python Description : A Python implementation of JSON Web Token draft 01. This library provides a means of representing signed content using JSON data structures, including claims to be transferred between two parties encoded as digitally signed and encrypted JSON objects. -------------------------------------------------------------------------------- Update Information: Latest upstream with security fix for https://seclists.org/oss-sec/2015/q2/3 https://github.com/jpadilla/pyjwt/commit/88a9fc56bdc6c870aa6af93bda401414a217db2a -------------------------------------------------------------------------------- References: [ 1 ] Bug #1231173 - python-jwt: token verification bypass with "none" algorithm https://bugzilla.redhat.com/show_bug.cgi?id=1231173 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update python-jwt' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . The most recent patch for python-jwt resolves a serious token validation flaw identified in Fedora 21, ensuring expedited security improvements.. python-jwt Update,Fedora Security,Token Verification Bypass,Security Update,JSON Web Token. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 30, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200