CVE-2020-28453

Read Time:6 Second

This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.

Read More

Opsera’s GitCustodian detects vulnerable data in source code

Read Time:38 Second

DevOps orchestration platform provider Opsera has announced the launch of GitCustodian, a new Software-as-a-Service (SaaS) product that detects and reports vulnerable data in code repositories including Gitlab, Github, and Bitbucket.

GitCustodian scans the code repositories for vulnerable data and alerts security and DevOps teams so that they can prevent vulnerabilities from leaking into production, protecting software development pipelines. Once vulnerabilities are found, the solution automates the remediation process for any uncovered secrets or other sensitive artifacts, Opsera says.

The release comes at a time of heightened awareness around data leaks in source code repositories. In April, GitHub revealed that attackers had used stolen authorization tokens to download private data stored on the platform.

To read this article in full, please click here

Read More