ZDI-23-1719: ManageEngine Recovery Manager Plus getEscapedValue Command Injection Remote Code Execution Vulnerability

Read Time:13 Second

This vulnerability allows remote attackers to execute arbitrary code on affected installations of ManageEngine Recovery Manager Plus. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2023-48646.

Read More

dbus-broker-28-4.el8

Read Time:12 Second

FEDORA-EPEL-2023-330054b0a8

Packages in this update:

dbus-broker-28-4.el8

Update description:

This update backports the patches from the RHEL 9 package to this EPEL 8 package. Notable, these patches fix CVE-2022-31212 and CVE-2022-31213.

Read More