Threats Tagged 'ghsa-jhp3-fv3p-rj5c'
View all threats tagged with 'ghsa-jhp3-fv3p-rj5c'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-jhp3-fv3p-rj5c'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-18918: CWE-863 in Eclipse Foundation Eclipse LyoCVE-2026-18918 0 In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilter`, are vulnerable. An attacked can create a provisional trusted client (valid use-case) but then it can be used as a trusted client immediately without requiring the administrator approval to clear the provisional status. The 3-legged path requiring user interaction is not vulnerable and rejects provisional clients. Join the discussion | CVE Database V5 | 08/28/2026, 08:54:07 UTC Added: 08/28/2026, 11:22:47 UTC |
Showing 1 to 1 of 1 result