Vulnerabilities & PatchesEmerging1 src
Issue 231: API authentication bypass in Ivanti Sentry, Docker images expose API and keys
This week, we have news of an API authentication bypass vulnerability in the Ivanti Sentry cybersecurity product and a report into Docker images that are exposing APIs and private keys. We also have articles on API security’s role in protecting retail apps, how APIs and generative AI interoperate, and how attackers bypass Web Application Firewalls.
We conclude with Dana Epp showing how to use Postman Flows for exploiting APIs.
Vulnerability: API authentication bypass in Ivanti Sentry
First up this week is news of a vulnerability in the Ivanti Sentry cybersecurity product. The vulnerability (tracked as CVE-2023-38035 ) impacts versions 9. 18 and earlier of the product.
The vulnerability allows an attacker to access an administration API endpoint (running on port 8443 by default) without any authentication at all.