home.social

#cve202321932 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve202321932, aggregated by home.social.

  1. At some stage, we need to talk about Oracle product security.

    - Oracle Opera vulnerability CVE-2023-21932.
    - Preauth RCE, GET request to cgi-bin script.
    - Oracle didn’t produce a patch for one year and downplayed severity.
    - This software is used by almost all of the largest hotel chains around the world.
    - This critical piece of software holds all of the PII for every guest, including but not limited to credit card details.

    blog.assetnote.io/2023/04/30/r #OracleOpera #CVE202321932